IPDebrief

54.37.118.90

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

## IP INTELLIGENCE BRIEFING

Target IP: 54.37.118.90/32

Classification: Moderate Risk

Date: Current Intelligence Cycle

---

EXECUTIVE SUMMARY

IP 54.37.118.90 is a cloud infrastructure asset operated by OVH within the Ahrefs Pte Ltd Dmytro organization. The IP carries a risk score of 40 (Moderate Risk) and is associated with the 54.37.0.0/16 BGP prefix under ASN 16276. While no active threat indicators are present, the IP resides in a high-abuse-density subnet (54.37.118.0/24) with 25 of 32 sibling IPs exhibiting threat characteristics.

---

OWNERSHIP AND GEOLOCATION

AttributeValue
**Organization**Ahrefs Pte Ltd Dmytro
**ASN**16276
**ISP/Provider**OVH (CloudCompute/Hosting)
**Geolocation**France (FR), Europe/Paris timezone
**Geographic Consensus**1 source, consensus verified
**Registration**ARIN RIR

---

THREAT INDICATORS

---

NETWORK INFRASTRUCTURE

---

NEIGHBORHOOD ANALYSIS (54.37.118.0/24)

The subnet exhibits elevated abuse characteristics. All 31 observed neighbors maintain risk scores between 40-50 with authority scores at 50, indicating consistent cloud infrastructure usage with moderate risk profiles.

---

OBSERVATION HISTORY

Total observations: 19 signals

The IP shows minimal temporal volatility with no persistent malicious activity detected. Signals indicate stable ownership with periodic monitoring across subnet abuse density, operator scoring, and multi-dimensional risk assessments.

---

SECURITY ACTIONS AND RECOMMENDATIONS

Risk-Based Classification: Moderate Risk (Score 40)

Recommended Firewall Rules:

```bash

# iptables

iptables -A INPUT -s 54.37.118.90 -j DROP

# nftables

nft add rule inet filter input ip saddr 54.37.118.90 drop

# nginx

deny 54.37.118.90;

# pfSense

54.37.118.90/32

# Cloudflare WAF

{"description":"Block 54.37.118.90 โ€” IPDebrief risk score 40","action":"block","filter":{"expression":"ip.src eq 54.37.118.90"}}

# AWS WAF

{"Addresses":["54.37.118.90/32"],"Description":"IPDebrief risk 40"}

```

Action Notes: No specific security action recommendations generated. The IP is classified as moderate risk with no active threat indicators. Blocking should be considered based on organizational risk tolerance and correlation with other traffic analysis signals.

---

INTELLIGENCE CONCLUSIONS

1. Legitimate Cloud Infrastructure: The IP operates within OVH cloud hosting infrastructure associated with Ahrefs, a known search engine marketing tool provider.

2. Subnet Context: The 54.37.118.0/24 subnet demonstrates high abuse density (0.7812), suggesting shared infrastructure usage patterns typical of cloud environments.

3. No Active Threats: No blacklist entries, known campaigns, or threat indicators detected.

4. Monitoring Recommendation: While the IP is not actively malicious, the elevated neighborhood abuse density warrants continued monitoring, particularly for anomalous traffic patterns.

---

*Report generated from IPDebrief intelligence platform. All data sourced from real-time network observation and analysis.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ซ๐Ÿ‡ท France
Regionโ€”
Cityโ€”
TimezoneEurope/Paris
Latitude48.86
Longitude2.34

๐Ÿข Ownership & Registration

OrganizationAhrefs Pte Ltd Dmytro
ASNAS16276
Network Nameโ€”
CIDR Blockโ€”
RIRARIN
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRproxy-fr000-san90.ahrefs.net
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-fr000-san90.ahrefs.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
33%
24
routing
13%
11
services
12%
22
ownership
24%
23
reputation
31%
13
geolocation
25%
22
Overall23%1015
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-20 17:48:44 UTC
Last Seen2026-06-28 12:27:30 UTC
Profile Built2026-06-29 06:32:03 UTC
Data FreshnessLive
Signal Types21
Total Observations25
๐Ÿ” 21 signal types ยท 25 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.