# IP Intelligence Briefing: 94.23.188.218/32
Date: 2026-06-24
IP Address: 94.23.188.218
Risk Assessment: Moderate Risk (Score: 50/100)
## Executive Summary
The target IP address 94.23.188.218 is registered to OVH SAS (AS16276), a cloud hosting provider headquartered in Roubaix, Hauts-de-France, France. The IP resolves to hostnames under the ahrefs.net domain (proxy-fr008-san218.ahrefs.net) and operates within a high-abuse density subnet (94.23.188.0/24). Multiple security signals indicate the IP has been listed on 8 threat feeds with at least one high-severity classification. The subnet exhibits elevated abuse density (0.8125) with 26 of 32 sibling IPs classified as threat-siblings.
## Ownership and Infrastructure
- ASN: AS16276 (OVH SAS)
- Organization: Ahrefs Pte Ltd Dmytro
- Network Block: 94.23.0.0/16
- Geolocation: Roubaix, Hauts-de-France, France (EUR/Paris timezone)
- Infrastructure Type: Cloud Compute / Hosting
- Network Classification: Cloud infrastructure with no services currently exposed (firewalled)
## Threat Indicators
- Blacklist Status: Listed on 8 threat feeds; 2 listings with high severity observed as of 2026-06-24
- Operator Score: 0.1 (Minimal risk from operator perspective)
- Threat Persistence: No persistent malicious activity detected; threat observation count: 1
- Reputation Sources: Multiple feeds associated with the IP
- DNSBL Lists: 1 DNSBL listing confirmed; 8 total DNSBL total lists
## Neighborhood Analysis
The /24 subnet 94.23.188.0/24 demonstrates high abuse density with the following characteristics:
- Total Siblings: 32 IPs
- Active Siblings: 12
- Threat Siblings: 26 (81.25% of subnet)
- Neighbor Risk Distribution: Medium risk classification (40-50 score range)
- Notable Neighbors: 94.23.188.219, 94.23.188.220, 94.23.188.221, 94.23.188.223 all carry risk scores of 50
The elevated neighbor risk scores suggest potential coordinated hosting or compromised infrastructure within this subnet.
## Observation History
Signal history reveals 25 observations tracked over the monitoring period. Key findings include:
- 2026-06-24: Recent blacklist activity with high-severity classifications; operator score of 0.1
- 2026-06-19: Subnet abuse density classified as high_abuse (0.8125); ASN associated with known threats on multiple pulse feeds
- Stability: No ownership changes detected; threat persistence days: 0
## Recommended Security Actions
Based on the risk profile, the following firewall rules are recommended for immediate deployment:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 94.23.188.218 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 94.23.188.218 drop` |
| nginx | `deny 94.23.188.218;` |
| pfSense | `94.23.188.218/32` |
| Cloudflare WAF | Block IP 94.23.188.218 |
| AWS WAF | Add 94.23.188.218/32 to block list |
## Analyst Notes
The IP address shows characteristics consistent with hosting infrastructure rather than active attack vectors. However, the high abuse density of the parent subnet and multiple blacklist listings warrant monitoring. The IP is associated with legitimate hosting (OVH) but demonstrates threat indicators that suggest either hosting of compromised endpoints or involvement in abuse campaigns. Recommend correlating with internal threat detection logs and maintaining blocking measures while monitoring for activity patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-fr008-san218.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-fr008-san218.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 24% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:43 UTC |
| Last Seen | 2026-06-27 09:45:53 UTC |
| Profile Built | 2026-06-28 03:51:24 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 29 |
Full dossier details are available via our API.