IP INTELLIGENCE BRIEFING: 54.37.118.76/32
1. Executive Summary
IP 54.37.118.76 presents a moderate risk profile (Risk Score: 40) with characteristics consistent with legitimate hosting infrastructure. The address resolves to the Ahrefs domain and is hosted on OVH infrastructure in France. No active malicious indicators were detected, though the /24 subnet exhibits elevated abuse density.
2. Technical Profile
- Risk Classification: Moderate Risk (Score: 40/100)
- Network Provider: OVH (ASN 16276)
- Organization: Ahrefs Pte Ltd Dmytro
- Geolocation: France (FR) - Europe/Paris timezone
- Infrastructure Type: Cloud/Hosting
- Network Role: Hosting provider (firewalled, no active services detected)
- DNS Resolution: proxy-fr000-san76.ahrefs.net (ahrefs.net)
3. Threat Assessment
- Threat Indicators: None detected (blacklist count: 0, not known attacker, not spam source)
- DNSBL Status: Listed on 1 of 8 evaluated threat feeds
- Campaign Association: No correlations to known threat campaigns
- Behavioral Activity: No honeypot hits, enumeration strikes, or WAF violations observed
- Persistence: Threat observation count: 1; not persistently malicious
4. Neighborhood Analysis (54.37.118.0/24)
- Subnet Classification: High abuse density (0.6562)
- Total Siblings: 32 IP addresses
- Active Siblings: 23
- Threat Siblings: 21
- Neighbor Risk Distribution: All 31 neighboring IPs classified as medium risk (Scores: 40-50)
- Inherited Risk Score: 26
- Interpretation: The /24 subnet shows consistent medium-risk scoring across all neighbors, indicating legitimate but densely utilized hosting infrastructure rather than concentrated malicious activity.
5. Historical Observations
- Total Signals: 23 observations tracked
- Ownership Stability: No ownership changes detected
- Recent Classifications: Consistent cloud/compute infrastructure designation with France geolocation
- Temporal Risk Trend: Stable; no escalation in risk profile over observation period
6. Operational Classification
- Control Plane: Route stable (0 changes in 30 days); DNSSEC valid; CAA records present
- Services: No open ports detected (firewalled)
- TLS/HTTP: No active web services or certificates observed
- Anycast/Proxy: Not detected
7. Recommended Actions
- Blocking: Not recommended. IP resolves to legitimate hosting provider (OVH) with Ahrefs domain association.
- Monitoring: Continue monitoring due to elevated neighborhood abuse density. Monitor for behavioral changes.
- Allow List: Consider whitelisting if traffic originates from this IP and is verified as legitimate Ahrefs infrastructure.
- Firewall Rules: No specific block rules required. Standard egress filtering applies.
8. Intelligence Summary
IP 54.37.118.76 represents legitimate hosting infrastructure associated with Ahrefs Pte Ltd. The moderate risk score reflects the high-abuse neighborhood environment rather than IP-specific malicious activity. No immediate threat action is warranted. SOC teams should maintain awareness of the subnet's elevated abuse density context when evaluating traffic patterns from this range.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-fr000-san76.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-fr000-san76.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:27 UTC |
| Last Seen | 2026-06-27 07:48:48 UTC |
| Profile Built | 2026-06-28 01:55:16 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 28 |
Full dossier details are available via our API.