IP Intelligence Briefing: 54.38.147.217
Date: 2026-06-14
---
**1. Core Profile**
- Risk Score: 25 (Low Risk)
- Provider: OVH (ASN 16276)
- Organization: Ahrefs Pte Ltd (Dmytro)
- Geolocation: London, England, UK (GeoPlausible: False)
- Network Role: Hosting provider (CloudCompute)
- Threat Indicators: No malicious activity detected (no blacklists, campaigns, or DNS anomalies).
---
**2. Observation History**
- Last 30 Days: Consistently classified as "Minimal Risk" (Operator Score: 0.2174).
- Key Trends:
- No significant changes in geolocation, DNS, or threat signals.
- Subnet (54.38.147.217/24) shows moderate abuse density (0.4297), with 110/256 IPs flagged as "threat siblings."
---
**3. Relationships**
- Network: Linked to OVH subnet OVH_282347341 (same /24 subnet).
- DNS: Resolves to `proxy-uk005-san217.ahrefs.net` (Ahrefs Pte Ltd).
- Certificates: No TLS certificates or DNSSEC validation anomalies.
---
**4. Neighborhood Analysis**
- Subnet: 54.38.147.217/24 (256 IPs).
- Risk Distribution:
- Low Risk: 66 IPs (avg. score: 25).
- Medium Risk: 34 IPs (avg. score: 40).
- High Risk: 0 IPs.
- Abuse Density: 42.97% of siblings show suspicious behavior (e.g., spam, C2, or phishing).
---
**5. Recommendations**
- Monitor Subnet: Track new high-risk IPs in the 54.38.147.0/24 range.
- Verify Hosting: Confirm Ahrefs Pte Ltdโs compliance with hosting security standards.
- Check DNS: Ensure `proxy-uk005-san217.ahrefs.net` is not associated with malicious domains.
- Firewall Rules: Consider blocking high-risk neighbors if traffic patterns suggest lateral movement.
---
Conclusion: The IP itself is low risk, but its subnet exhibits moderate abuse density. SOC teams should prioritize monitoring the broader network for emerging threats while ensuring the IPโs hosting environment remains secure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk005-san217.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk005-san217.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 23% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:28 UTC |
| Last Seen | 2026-06-27 07:53:00 UTC |
| Profile Built | 2026-06-28 01:59:48 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 29 |
Full dossier details are available via our API.