## IP Intelligence Briefing: 54.38.147.192/32
Executive Summary
IP 54.38.147.192 is a cloud-hosted infrastructure endpoint belonging to Ahrefs Pte Ltd, operating within the OVH network (ASN 16276). The IP carries a moderate risk score of 40 and resides in a subnet classified as "high_abuse" with 62% abuse density. No direct threat indicators or known campaigns were identified. Recommended action: monitor traffic patterns or block based on organizational policy.
---
Infrastructure Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 40 (Moderate) |
| **ASN** | 16276 (OVH) |
| **Organization** | Ahrefs Pte Ltd Dmytro |
| **Location** | London, England, GB |
| **Network Role** | CloudCompute / Hosting |
| **DNS Hostname** | proxy-uk005-san192.ahrefs.net |
| **Domain** | ahrefs.net |
| **Infrastructure Type** | Cloud-based hosting |
---
Threat Assessment
Direct Indicators:
- No known threat indicators in threat feeds
- Not classified as Tor exit node, known attacker, or spam source
- Blacklist count: 0
- DNSBL listings: 1 of 8 total lists
Contextual Risk Factors:
- Subnet 54.38.147.0/24 classified as "high_abuse"
- Abuse density: 0.6211 (62% of active IPs flagged)
- 159 out of 256 subnet IPs classified as threat siblings
- Inherited risk score: 24
---
Observation History
Total observations: 25
Key Timeline:
- 2026-06-20T14:23:07: Routing and ownership signals collected (confidence: 0.29-0.85)
- 2026-06-15T14:57:26: Port scanning detected (multiple ports probed)
- 2026-06-15T14:37:28: ASN 16276 allocation verified (age: 9,251 days, registered RIPE NCC, FR)
Behavioral Indicators:
- Risk score stable at 40
- No observed ownership changes
- Threat observation count: 1
- Not persistently malicious
---
Network Relationships
Total relationships: 38
Primary Connections:
- Multiple relationships to network identifier OVH_282347341
- BGP prefix: 54.38.0.0/16
- AS Path: 57866 โ 16276
- Route stability: Stable (no route changes in 30 days)
- DNSSEC: Valid
- RPKI state: Consistent
---
Recommended Security Actions
The following firewall rules are generated based on risk profile:
Recommended Action: Block or monitor based on organizational policy
| Platform | Rule |
|---|---|
| **iptables** | `iptables -A INPUT -s 54.38.147.192 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 54.38.147.192 drop` |
| **nginx** | `deny 54.38.147.192;` |
| **pfSense** | `54.38.147.192/32` |
| **Cloudflare WAF** | Block IP 54.38.147.192 (risk score 40) |
| **AWS WAF** | Add address 54.38.147.192/32 |
---
Analyst Notes
1. Legitimate Use Case: IP resolves to Ahrefs proxy hostname (ahrefs.net), indicating legitimate SEO/analytics infrastructure.
2. Subnet Risk: The parent subnet (54.38.147.0/24) shows high abuse density. Contextual monitoring of neighboring IPs may reveal coordinated activity.
3. No Open Services: Port scanning detected but no services currently open on this specific IP.
4. Risk Mitigation: Given the moderate risk score and legitimate ownership, blocking is recommended only if traffic patterns indicate abuse or if organizational policy requires subnet-wide restrictions.
---
*Intelligence generated via IPDebrief analytical tools. All data sourced from network reputation databases and historical observation logs.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | 54.38.0.0/16 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk005-san192.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk005-san192.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 33% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 37% | 3 | 6 |
| reputation | 31% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 28% | 12 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 21:01:01 UTC |
| Last Seen | 2026-06-28 16:31:15 UTC |
| Profile Built | 2026-06-29 04:36:15 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 29 |
Full dossier details are available via our API.