# IP Intelligence Briefing: 54.38.147.231/32
Classification: Moderate Risk | Date: June 2026
IP Address: 54.38.147.231
---
## Executive Summary
IP 54.38.147.231 is a cloud computing endpoint operating within the OVH infrastructure (ASN 16276) with a risk score of 50. The IP resolves to the ahrefs.net domain and is hosted in London, England. While the IP itself shows no active open ports or services, its neighborhood exhibits elevated abuse activity, warranting defensive monitoring.
---
## Ownership and Infrastructure
- ASN: 16276 (OVH)
- Organization: Ahrefs Pte Ltd Dmytro
- Geolocation: London, England, GB (750km accuracy radius)
- Network Role: CloudCompute, Hosting infrastructure
- DNS PTR: proxy-uk005-san231.ahrefs.net
- Service Status: Firewalled / No Services detected
---
## Threat Assessment
- Risk Score: 50 (Moderate)
- Threat Indicators: None directly associated
- Blacklist Status: 0 blacklists, 2 DNSBL listings
- Abuse Confidence: Not scored
- Known Campaigns: None identified
- Tor/Proxy: Not identified as Tor exit node, proxy, or VPN
---
## Neighborhood Context
The /24 subnet (54.38.147.0/24) demonstrates elevated abuse characteristics:
- Abuse Density: 0.6367 (high_abuse classification)
- Active Siblings: 193 of 256 total IPs
- Threat Siblings: 163 IPs flagged as threats
- Inherited Risk Score: 25
Risk distribution across neighborhood:
- High risk: 0 siblings
- Medium risk: 69 siblings
- Low risk: 31 siblings
This contextual risk factor suggests the subnet may be shared hosting or a service provider environment with mixed-use cases.
---
## Historical Signals
Twenty-five observations recorded, most recent on June 20, 2026:
- Consistent high_abuse classification in subnet-level signals
- Domain resolution to ahrefs.net confirmed (80% confidence)
- Geographic inference to GB with 28% confidence
- Operator score: 0.4348 (Basic classification)
- No persistent malicious behavior observed
---
## Relationship Network
56 relationships identified, primarily:
- Same network associations (OVH_282347341)
- Multiple network-level linkages indicating shared infrastructure
---
## Defensive Recommendations
Immediate Actions:
1. Block at perimeter firewall per automated recommendations:
```
iptables -A INPUT -s 54.38.147.231 -j DROP
```
Equivalent rules available for nftables, pfSense, Cloudflare WAF, and AWS WAF.
2. Monitor neighborhood activity โ 163 threat siblings in the /24 subnet warrant correlation analysis.
3. No immediate service-based blocking required โ IP shows no open ports or active services.
Contextual Considerations:
- Low-risk classification (risk score 50) allows for monitoring rather than aggressive blocking
- No evidence of active malicious activity at the IP level
- High neighborhood abuse density suggests broader subnet-level risk
---
Analyst Notes: This IP represents a cloud hosting endpoint within a high-abuse density subnet. While the IP itself shows moderate risk, the neighborhood context and DNS resolution to a known service domain (ahrefs.net) suggest legitimate use cases may coexist with abusive actors. Implement firewall rules per automated recommendations and maintain correlation with neighborhood threat activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | 54.38.0.0/16 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk005-san231.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk005-san231.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 20% | 2 | 3 |
| services | 12% | 2 | 2 |
| ownership | 24% | 3 | 4 |
| reputation | 22% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 12 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-17 03:09:20 UTC |
| Last Seen | 2026-06-28 04:39:58 UTC |
| Profile Built | 2026-06-28 22:44:48 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 31 |
Full dossier details are available via our API.