IP Intelligence Briefing: 92.222.104.203
*Generated via IPDebrief analysis*
---
**Key Risk Indicators**
- Risk Score: 40 (Moderate Risk)
- Provider: OVH (CloudCompute infrastructure)
- Ownership: Ahrefs Pte Ltd Dmytro (legitimate entity)
- Geolocation: Paris, France (FR)
- Network Role: Hosting provider infrastructure (cloud-based, no direct services exposed)
- Threat Status: No malicious indicators, no known campaigns, no blacklist entries
---
**Observation History**
- Recent Signals:
- DNS records linked to `proxy-fr006-san203.ahrefs.net` (Ahrefs subdomain).
- Network classification as "CloudCompute" with OVH provider.
- DNSSEC and CAA records validated, no domain misconfigurations.
- Trend: No significant changes in risk profile over the past 30 days.
---
**Network Relationships**
- Subnet: 92.222.104.203/24
- Neighbors:
- 31 IPs in subnet, 28 actively reported.
- Abuse Density: 71.88% (high abuse risk in subnet).
- Threat Siblings: 23 IPs with elevated risk scores (40โ50).
- Associations:
- Linked to OVH network `OVH_282114231`.
- DNS hostname `proxy-fr006-san203.ahrefs.net` (Ahrefs Pte Ltd).
---
**Subnet Context**
- Abuse Classification: High abuse density (0.7188).
- Neighbor Risk: Most IPs in subnet have moderate risk scores (40โ50), suggesting potential for malicious activity within the same infrastructure.
- Subnet Stability: Route stability flagged as "low" (IPDebrief).
---
**Actionable Intelligence**
1. Monitor Subnet: High abuse density in the 92.222.104.0/24 subnet warrants closer inspection of neighboring IPs.
2. Verify DNS Associations: Confirm legitimacy of `proxy-fr006-san203.ahrefs.net` (Ahrefs is a legitimate company, but ensure no subdomain hijacking).
3. Network Segmentation: Consider isolating cloud-based infrastructure to limit lateral movement risks.
4. Threat Hunting: Investigate if any of the 23 high-risk sibling IPs are linked to malicious campaigns or C2 activity.
---
Conclusion:
The IP 92.222.104.203 is associated with legitimate cloud infrastructure (OVH, Ahrefs), but its subnet exhibits high abuse density. While the IP itself shows no direct malicious indicators, the environment may host other risky assets. SOC teams should prioritize monitoring the subnet and validating DNS/ownership relationships.
*Generated by IPDebrief | Last Updated: 2026-06-15*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | 92.222.0.0/16 |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-fr006-san203.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-fr006-san203.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 2 |
| routing | 27% | 2 | 3 |
| services | 8% | 1 | 1 |
| ownership | 35% | 3 | 6 |
| reputation | 22% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 25% | 11 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 21:41:14 UTC |
| Last Seen | 2026-06-28 10:25:58 UTC |
| Profile Built | 2026-06-29 04:30:37 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 28 |
Full dossier details are available via our API.