# IP INTELLIGENCE BRIEFING: 54.38.147.174/32
Generated: 2026-06-14 | Classification: Moderate Risk
---
## EXECUTIVE SUMMARY
IP 54.38.147.174 presents a moderate risk profile (score: 40) operating within OVH cloud infrastructure in London, GB. The IP resolves to an Ahrefs proxy hostname and is situated in a high-abuse-density subnet. While no active threat indicators were observed, the neighborhood context warrants defensive consideration.
---
## OWNERSHIP AND INFRASTRUCTURE
- ASN: AS16276 (OVH SAS)
- Organization: Ahrefs Pte Ltd Dmytro
- CIDR Block: 54.38.0.0/16
- Infrastructure Type: CloudCompute
- Hosting Provider: OVH
- Geolocation: London, England, GB (consensus: true)
- Timezone: Europe/London
---
## THREAT INDICATORS
- Risk Score: 40 (Moderate)
- Abuse Confidence Score: Not available
- Blacklist Status: Listed on 1 of 8 DNSBLs
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Campaign Correlation: None detected
---
## NETWORK CONTEXT AND NEIGHBORHOOD
Subnet Analysis: 54.38.147.0/24
- Abuse Density: 0.5039 (High abuse)
- Classification: high_abuse
- Total Siblings: 256
- Active Siblings: 168
- Threat Siblings: 129
- Inherited Risk: 20
Risk Distribution in Subnet:
- High Risk: 0
- Medium Risk: 88
- Low Risk: 12
---
## OBSERVATION HISTORY (22 Observations)
Recent signals indicate consistent cloud infrastructure classification with provider OVH. Geolocation signals show mixed consensus:
- June 14, 2026: Cloud infrastructure (OVH), hosting enabled
- Geolocation Signals: Confirmed GB location with 750km accuracy radius
- Network Stability: Route changes within 30-day period: 0
- DNSSEC Status: Valid
---
## DNS AND HOSTING
- PTR Hostname: proxy-uk005-san174.ahrefs.net
- Forward Resolution: 54.38.147.174 โ proxy-uk005-san174.ahrefs.net
- Domain: ahrefs.net
- Open Ports: None detected (Firewalled / No Services)
- Email Auth: SPF/DMARC not configured
---
## RECOMMENDED ACTIONS
Block at Perimeter:
```bash
# iptables
iptables -A INPUT -s 54.38.147.174 -j DROP
# nftables
nft add rule inet filter input ip saddr 54.38.147.174 drop
# NGINX
deny 54.38.147.174;
```
Cloud Provider WAF Rules:
- Cloudflare WAF: Block with expression `ip.src eq 54.38.147.174`
- AWS WAF: Add IP 54.38.147.174/32 to rule set
---
## ANALYST NOTES
The IP resolves to an Ahrefs proxy hostname (proxy-uk005-san174.ahrefs.net), indicating legitimate SaaS usage. However, the high abuse density of the /24 subnet (129 threat siblings) suggests shared infrastructure risks. The single DNSBL listing warrants monitoring. No active exploitation patterns observed, but defensive blocking is recommended due to neighborhood context and moderate risk score.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk005-san174.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk005-san174.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 23% | 2 | 2 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-10 16:14:41 UTC |
| Last Seen | 2026-06-27 18:06:11 UTC |
| Profile Built | 2026-06-28 12:10:21 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 27 |
Full dossier details are available via our API.