# IP Intelligence Briefing: 54.38.147.198/32
## Executive Summary
IP 54.38.147.198 is a moderate-risk cloud computing endpoint hosted by OVH in London, England, operating under Ahrefs Pte Ltd infrastructure. The IP shows elevated threat characteristics within a high-abuse subnet environment and multiple blacklist listings. No active services were detected, and the address resolves to a proxy hostname associated with ahrefs.net.
## IP Profile
- Risk Score: 50 (Moderate Risk)
- ASN: 16276 (OVH)
- Organization: Ahrefs Pte Ltd Dmytro
- Geolocation: London, England, GB
- Infrastructure Type: CloudCompute, Hosting
- Network Classification: Cloud, Not CDN/VPN/Proxy
## Threat Assessment
Indicators:
- Listed on 8 DNSBLs with 2 confirmed listings
- Maximum severity: High
- No Tor exit node activity
- No known campaign correlations
- No open ports detected (firewalled/no services)
Control Plane:
- Route stability: False (isRouteStable)
- RPKI state: Not reported
- DNSSEC: Valid
- DNSBL listings: 2 confirmed across 8 total lists
## Neighborhood Analysis
Subnet 54.38.147.0/24 demonstrates elevated abuse characteristics:
- Abuse Density: 0.6875 (high_abuse classification)
- Active Siblings: 210/256 total IPs
- Threat Siblings: 176
- Inherited Risk Score: 27
- Neighbor Risk Distribution: 84 low, 16 medium, 0 high
This contextualizes the target within a high-density hosting environment.
## Observation History
Twenty-one signal observations recorded:
- Recent high-severity blacklist listings observed (June 2026)
- Geolocation data shows 500.4km distance from claimed London coordinates (plausible validation)
- Network role consistently classified as cloud/hosting
- DNS records stable (ahrefs.net domain)
## DNS/Email Infrastructure
- PTR Hostname: proxy-uk005-san198.ahrefs.net
- Forward Resolution: proxy-uk005-san198.ahrefs.net
- Email Authentication: No SPF or DMARC records configured
- CAA Records: Present and valid
## Recommended Security Actions
Block at Network Perimeter:
```bash
iptables -A INPUT -s 54.38.147.198 -j DROP
nft add rule inet filter input ip saddr 54.38.147.198 drop
```
WAF Rules:
- Cloudflare WAF: Block with expression `ip.src eq 54.38.147.198`
- AWS WAF: Add `54.38.147.198/32` to address set
Contextual Note: Given the high-abuse neighborhood classification and multiple blacklist listings, consider blocking the broader 54.38.147.0/24 subnet or applying rate limiting to the /16 prefix (54.38.0.0/16) if false positives are acceptable.
## SOC Analyst Guidance
This IP presents moderate risk within a known high-abuse OVH hosting environment. The combination of blacklist listings, high-density threat sibling activity, and lack of email authentication controls warrants defensive action. No evidence of active scanning or service enumeration was detected, but the contextual risk profile supports blocking at the firewall level.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk005-san198.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk005-san198.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 20% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 39% | 2 | 3 |
| Overall | 22% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 09:13:38 UTC |
| Last Seen | 2026-06-28 19:04:20 UTC |
| Profile Built | 2026-06-29 07:08:58 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.