## IP Intelligence Briefing: 54.38.147.150
Classification: Moderate Risk - Infrastructure Node
Report Date: Current Assessment
IP Address: 54.38.147.150/32
Risk Score: 40/100
Executive Summary
The target IP (54.38.147.150) is a cloud infrastructure endpoint operated by Ahrefs Pte Ltd Dmytro under AS16276 (OVH). The address resolves to proxy-uk005-san150.ahrefs.net and is geolocated to London, England. While the IP itself shows moderate risk scoring, it resides within a subnet (54.38.147.0/24) classified as high-abuse density. The infrastructure is actively maintained and firewalled with no open services detected.
Technical Profile
- ASN: 16276 (OVH)
- Organization: Ahrefs Pte Ltd Dmytro
- Geolocation: London, England, GB
- Infrastructure Type: CloudCompute/Hosting
- DNS: proxy-uk005-san150.ahrefs.net
- PTR Record: proxy-uk005-san150.ahrefs.net
- Services: None detected (firewalled)
- Open Ports: None
Threat Assessment
The IP shows minimal direct malicious indicators. Key observations:
- Direct Threats: None identified. Not listed on known threat feeds.
- Blacklist Status: Listed on 1 of 8 DNSBL sources.
- Abuse Confidence: Score unavailable.
- Campaign Activity: No certificate matches or correlated IPs.
- Persistence: Not persistently malicious; 0 threat observation days.
Neighborhood Analysis
Subnet 54.38.147.0/24 exhibits elevated abuse characteristics:
- Abuse Density: 0.5195 (High Abuse Classification)
- Inherited Risk: 20
- Subnet Size: 256 total IPs
- Active IPs: 178
- Threat IPs: 133 (51.5% of active addresses)
- Risk Distribution: 100 medium-risk neighbors sampled
Assessment: The IP shares infrastructure with a high-abuse subnet. This contextual risk is primarily due to neighboring addresses rather than the target IP itself.
Temporal Analysis
Recent observations confirm stable operational characteristics:
- Operator Score: 0.2174 (Minimal)
- Geographic Validation: Plausible (London coordinates, 500.4 km distance, 85-95ms RTT)
- Route Stability: Unstable route changes in past 30 days
- DNSSEC: Valid
Relationship Graph
The IP maintains 35 documented relationships, predominantly:
- Same Network: OVH_282347341 (multiple instances)
Recommended Actions
1. Monitoring: No immediate blocking required. Monitor for behavioral changes.
2. Firewall Rules: No specific egress/ingress rules recommended based on risk profile.
3. Threat Intelligence: Add to watchlist for contextual awareness of high-abuse subnet environment.
SOC Analyst Notes
This IP represents legitimate cloud infrastructure for Ahrefs, a web analytics and SEO tools company. The moderate risk score reflects its hosting environment characteristics rather than malicious activity. The high-abuse subnet classification warrants contextual monitoring but does not indicate the IP itself is malicious. Traffic from this address should be evaluated against organizational policies for cloud provider connections.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk005-san150.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk005-san150.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 21:40:50 UTC |
| Last Seen | 2026-06-28 10:19:35 UTC |
| Profile Built | 2026-06-29 04:24:50 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.