# IP Intelligence Briefing: 94.23.188.202/32
## Executive Summary
IP address 94.23.188.202 is a Moderate Risk (Score: 40) infrastructure address hosted within OVH cloud infrastructure in Roubaix, France. The IP resolves to the ahrefs.net domain and operates as a cloud/hosting service with no open services detected. Despite moderate individual risk scoring, the IP resides within a /24 subnet exhibiting critical abuse characteristics.
## Technical Profile
- Risk Score: 40 (Moderate Risk)
- Provider: OVH (ASN 16276)
- Organization: Ahrefs Pte Ltd Dmytro
- Location: Roubaix, Hauts-de-France, FR (500km accuracy radius)
- Infrastructure Type: Cloud Compute / Hosting
- Network Classification: Cloud infrastructure with firewall configuration active
## DNS Resolution & Host Identity
- PTR Hostname: proxy-fr008-san202.ahrefs.net
- Forward Resolution: proxy-fr008-san202.ahrefs.net (ahrefs.net)
- Forward Confirmed: No
- HTTP Services: None detected (Firewalled / No Services)
- DNSSEC Valid: Yes
- CAA Records: Present
## Network Context & Abuse Environment
The IP resides in subnet 94.23.188.0/24, which demonstrates critical abuse characteristics:
- Subnet Abuse Density: 0.875 (Critical)
- Classification: high_abuse
- Threat Siblings: 28 of 32 sibling IPs flagged as threats
- Active Siblings: 13
- Inherited Risk: 35
This subnet-level abuse density suggests the IP operates in a shared hosting or datacenter environment with significant abuse activity, despite the individual IP's moderate risk score.
## Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- DNSBL Listings: 1 of 8 total lists
- Known Campaigns: None
- Campaign Likelihood: None
## Observed Behavior
Recent signal observations (2026-06-20) indicate:
- Cloud/hosting provider classification
- DNS infrastructure for legitimate ahrefs.net domain
- Abuse density signals at subnet level
- Geolocation inference from France
## Recommended Security Actions
Firewall Rules
```bash
# iptables
iptables -A INPUT -s 94.23.188.202 -j DROP
# nftables
nft add rule inet filter input ip saddr 94.23.188.202 drop
# nginx
deny 94.23.188.202;
# pfSense
94.23.188.202/32
# Cloudflare WAF
Block 94.23.188.202 โ IPDebrief risk score 40
# AWS WAF
Addresses: 94.23.188.202/32
Description: IPDebrief risk 40
```
## Intelligence Assessment
While IP 94.23.188.202 itself shows no direct threat indicators and maintains a moderate risk profile, the critical subnet abuse density (0.875) and high concentration of threat siblings (28/32) indicate this IP operates within a compromised or abuse-prone network environment. The moderate risk score may reflect legitimate hosting services operating alongside abusive tenants in the same OVH infrastructure.
Recommendation: Block traffic from this IP due to subnet-level abuse risk and inherited threat characteristics. Monitor for any service openings or behavioral changes in future observations.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-fr008-san202.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-fr008-san202.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 03:37:07 UTC |
| Last Seen | 2026-06-28 08:38:45 UTC |
| Profile Built | 2026-06-29 02:43:10 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.