# IP Intelligence Briefing: 92.222.108.115
## Executive Summary
IP 92.222.108.115 is classified as Moderate Risk (Score: 40). The address resolves to legitimate Ahrefs infrastructure (OVH Cloud, ASN 16276) but operates within a subnet exhibiting elevated abuse characteristics. No direct threat indicators were identified for this specific address.
## Ownership and Infrastructure
- Provider: OVH (ASN 16276)
- Organization: Ahrefs Pte Ltd Dmytro
- Geolocation: Paris, France (IDF Region)
- Infrastructure Type: CloudCompute / Hosting Environment
- DNS Resolution: proxy-fr002-san115.ahrefs.net
- Services: None detected (Firewalled / No Services)
- Network Classification: Cloud infrastructure with hosting capabilities
## Threat Assessment
- Risk Score: 40 (Moderate)
- Abuse Confidence Score: Not calculated
- Known Threats: None identified
- Blacklist Status: 0 listings
- Tor Exit Node: False
- Known Attacker: False
- Spam Source: False
The IP shows no direct threat indicators. However, the subnet context presents elevated risk considerations.
## Subnet Analysis (92.222.108.0/24)
- Abuse Density: 0.7419 (High Abuse Classification)
- Total Siblings: 31
- Active Siblings: 26
- Threat Siblings: 23
- Risk Distribution: 30 medium-risk IPs, 0 high-risk, 0 low-risk
The /24 subnet demonstrates significant abuse presence with 23 of 31 siblings flagged as threats. This contextual risk factor warrants monitoring.
## Temporal Analysis
- Total Observations: 23
- Observation Period: June 14โ19, 2026
- Operator Score: 0.2174 (Minimal)
- Threat Persistence: 0 days
- Ownership Changes: 0
Signal observations indicate stable ownership with no recent threat emergence. Geolocation validation confirms Paris coordinates with RTT metrics consistent with European location (avg RTT: 98.2ms).
## Network Relationships
- Primary Network: OVH_282114227
- Total Relationships: 58
- Route Stability: Unstable (isRouteStable: false)
- RPKI State: Not validated
- BGP Prefix: 92.222.0.0/16
## Recommended Actions
Immediate Mitigation
Firewall rules are recommended due to moderate risk score and subnet context:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 92.222.108.115 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 92.222.108.115 drop` |
| nginx | `deny 92.222.108.115;` |
| pfSense | `92.222.108.115/32` |
| Cloudflare WAF | Block IP (Risk Score 40) |
| AWS WAF | Add 92.222.108.115/32 to blocklist |
Monitoring Recommendations
1. Monitor subnet 92.222.108.0/24 for lateral threat activity
2. Track correlation with other Ahrefs infrastructure
3. Review incoming traffic patterns for the subnet
4. Re-evaluate if threat indicators emerge on sibling IPs
## Intelligence Conclusion
92.222.108.115 presents moderate risk primarily due to subnet abuse density rather than direct malicious activity. The IP belongs to legitimate Ahrefs infrastructure but shares hosting environment with 23 threat-sibling IPs. SOC analysts should apply blocking rules as precautionary measure while monitoring for changes in threat posture. No immediate threat indicators detected for this specific address.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-fr002-san115.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-fr002-san115.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:43 UTC |
| Last Seen | 2026-06-27 09:41:42 UTC |
| Profile Built | 2026-06-28 03:46:52 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 29 |
Full dossier details are available via our API.