IP Intelligence Briefing: 94.23.188.205
*Generated for SOC Analysts*
---
**1. IP Profile**
- Risk Score: 25 (Low Risk)
- Ownership: Owned by Ahrefs Pte Ltd Dmytro (OVH ASN 16276).
- Geolocation: Registered to France (FR), but no city/region data available.
- Network Role: Hosting provider (OVH), no public services detected (no open ports, TLS certs, or HTTP banners).
- Threat Indicators: No malicious activity, spam, or known attacker associations.
---
**2. Observation History**
- Risk Trends: Minimal risk over the past 30 days, with consistent low threat scores.
- DNS: Resolves to `proxy-fr008-san205.ahrefs.net` (Ahrefs server).
- Subnet Analysis:
- /24 Subnet: 94.23.188.0/24.
- Abuse Density: 43.75% (mixed risk, 14 malicious siblings out of 32).
- Active Neighbors: 9 IPs (2 medium-risk, 7 low-risk).
---
**3. Relationships**
- DNS Associations: Linked to `proxy-fr008-san205.ahrefs.net` (Ahrefs).
- Network: Part of OVH network (ASN 16276).
- Subnet: Shares network with 31 neighbors, including IPs with medium-risk scores.
---
**4. Network Context**
- Subnet Risk: Mixed risk due to 14 malicious neighbors.
- Neighbor Analysis:
- High-Risk Neighbors: 0
- Medium-Risk Neighbors: 23
- Low-Risk Neighbors: 8
- Abuse Density: 0.4375 (elevated risk in subnet).
---
**5. Recommendations**
- Monitor Subnet: Track medium-risk neighbors for potential lateral movement or shared infrastructure compromises.
- Verify Ahrefs Hosting: Confirm the IP is part of legitimate Ahrefs infrastructure and ensure no unauthorized access.
- Network Segmentation: Consider isolating this subnet if it hosts sensitive assets.
- DNS Monitoring: Watch for changes to `proxy-fr008-san205.ahrefs.net` or related domains.
---
Conclusion: This IP is associated with a legitimate hosting provider (Ahrefs) and shows no direct malicious activity. However, its subnet contains a notable number of medium-risk neighbors, warranting closer monitoring. No immediate mitigation is required, but ongoing observation is advised.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-fr008-san205.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-fr008-san205.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 38% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 25% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 15:39:42 UTC |
| Last Seen | 2026-06-28 09:32:57 UTC |
| Profile Built | 2026-06-29 03:37:49 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.