IP Intelligence Briefing: 54.38.147.131
*Generated via IPDebrief Analysis*
---
**Core Profile**
- Risk Score: 25 (Low Risk)
- Provider: OVH (ASN 16276)
- Organization: Ahrefs Pte Ltd (Dmytro)
- Geolocation: London, England, UK (High confidence)
- Network Role: CloudCompute infrastructure (Hosting, no residential/mobile traffic)
- Threat Indicators: No known malicious activity, no DNS/IP abuse, no TLS/HTTP anomalies.
---
**Observation History (Last 30 Days)**
- Stability: Route stability confirmed (BGP route unchanged).
- Activity Trends: No significant changes in geolocation, DNS, or threat signals.
- Key Metrics:
- 0 threat observations
- 1 DNS resolution (proxy-uk005-san131.ahrefs.net)
- 29 total signal observations (mixed confidence).
---
**Network Relationships**
- Linked Entities:
- Subnet: `54.38.147.131/24` (mixed classification, abuse density 45.31%)
- BGP Peer: OVH (ASN 16276)
- DNS: Ahrefs.net (CAA records, DNSSEC validated)
- Connections:
- 45+ relationships (primary link: same network as OVH_282347341).
---
**Neighborhood Analysis**
- Subnet: `54.38.147.131/24` (256 IPs)
- Risk Distribution:
- 55 IPs: Low risk (avg. 25)
- 45 IPs: Medium risk (avg. 40)
- Notable Neighbors:
- 54.38.147.0β4: Medium risk (25β40)
- 54.38.147.131: Low risk (25)
- Abuse Density: 45.31% (moderate risk in subnet).
---
**Threat Context**
- No Direct Malicious Activity: IP shows no signs of spam, C2, or exploitation.
- Network Context: Subnet contains both low-risk and medium-risk IPs. Monitor neighbors for lateral movement or shared infrastructure compromises.
- Provider Reputation: OVH is a legitimate cloud provider, but subnets with mixed abuse density require closer scrutiny.
---
**Recommended Actions**
1. Monitor Subnet: Track medium-risk neighbors for anomalies (e.g., sudden traffic spikes, DNS changes).
2. Verify DNS: Confirm Ahrefs.netβs legitimacy and ensure no spoofing.
3. Check Route Stability: Confirm BGP route persistence (no recent route changes).
4. Behavioral Analysis: Validate HTTP/TLS services (no banners, certs, or HTTP methods observed).
Conclusion: 54.38.147.131 is a low-risk IP associated with a legitimate cloud provider. However, its subnet contains medium-risk IPs, suggesting potential for shared infrastructure risks. Prioritize monitoring the subnet for indirect threats.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | β |
| CIDR Block | 54.38.0.0/16 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | proxy-uk005-san131.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk005-san131.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 20% | 2 | 3 |
| services | 12% | 2 | 2 |
| ownership | 24% | 3 | 4 |
| reputation | 22% | 1 | 2 |
| geolocation | 25% | 2 | 2 |
| Overall | 22% | 12 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-17 03:09:20 UTC |
| Last Seen | 2026-06-28 04:39:00 UTC |
| Profile Built | 2026-06-28 22:43:41 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 30 |
Full dossier details are available via our API.