IP Intelligence Briefing: 37.59.204.147
Date: 2026-06-14
---
**1. Core Profile**
- Risk Score: 40 (Moderate Risk)
- Ownership: Ahrefs Pte Ltd (OVH ASN 16276)
- Geolocation: France (FR)
- Network Role: CloudCompute (OVH infrastructure)
- Threat Indicators: No direct malicious activity detected.
---
**2. Observation History**
- Latest Activity: 2026-06-14
- Geolocation: Inferred as France (±500 km accuracy).
- Network Role: Confirmed as cloud-hosted infrastructure (OVH).
- Operator Risk: Minimal (operator score 0.2174).
- Abuse Density: High (subnet abuse density 0.7812).
---
**3. Relationships & Network Context**
- Subnet: 37.59.204.147/24
- Neighbors:
- 31 IPs in subnet (31 medium/high risk).
- 9 active siblings, 25 flagged as high-risk.
- Shared Network: OVH_282114232 (cloud provider network).
- DNS: Linked to `proxy-fr007-san147.ahrefs.net` (Ahrefs infrastructure).
---
**4. Threat & Risk Analysis**
- Subnet Risk: High abuse density (78.12%) with 25 high-risk neighbors.
- Neighbor Risks: 31 IPs in subnet have medium/high risk scores.
- No Direct Malicious Activity: No indicators of C2, phishing, or spam.
- Cloud Hosting: Likely a legitimate server, but shared hosting environments may introduce indirect risks.
---
**5. Recommendations**
- Monitor Subnet: Track activity in 37.59.204.147/24 for unusual traffic patterns.
- Verify DNS: Investigate `proxy-fr007-san147.ahrefs.net` for potential misconfigurations.
- Network Segmentation: Consider isolating high-risk neighbors to mitigate lateral movement risks.
- Threat Intelligence: Cross-reference with Ahrefsβ infrastructure for potential indirect compromises.
Conclusion: The IP is part of a high-risk subnet with shared hosting infrastructure. While no direct threats are detected, the environment warrants closer monitoring due to surrounding risks.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | β |
| CIDR Block | β |
| RIR | RIPE |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | proxy-fr007-san147.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-fr007-san147.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 22% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:18 UTC |
| Last Seen | 2026-06-27 05:07:17 UTC |
| Profile Built | 2026-06-27 23:13:25 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 25 |
Full dossier details are available via our API.