# IP Intelligence Briefing: 54.38.147.241/32
Classification: Low Risk | Risk Score: 25 | Status: Operational
---
## Executive Summary
IP address 54.38.147.241 is a cloud compute host operated by OVH (ASN 16276) for Ahrefs Pte Ltd Dmytro, located in London, England. The IP presents a low-risk profile with no active threat indicators, no blacklist listings, and no open services detected. However, the /24 subnet (54.38.147.0/24) exhibits mixed classification with elevated abuse density (0.4219), requiring contextual awareness.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **IP Address** | 54.38.147.241/32 |
| **Reputation** | Low Risk |
| **Risk Score** | 25 |
| **Provider** | OVH (ASN 16276) |
| **Organization** | Ahrefs Pte Ltd Dmytro |
| **Geolocation** | London, England, GB |
| **Network Type** | Cloud Compute / Hosting |
| **Infrastructure** | OVH_282347341 |
| **DNS Hostname** | proxy-uk005-san241.ahrefs.net |
| **Domain** | ahrefs.net |
---
## Threat Assessment
Current Indicators:
- Blacklist Status: Clean (0/8 DNSBL listings)
- Threat Feeds: No matches
- Tor/Proxy/Vpn: Not identified
- Open Ports: None detected
- Known Campaigns: None
- Abuse Confidence Score: Not applicable
Control Plane:
- BGP Prefix: 54.38.0.0/16
- Route Stability: Inconsistent (not stable)
- DNSSEC Valid: Yes
- Has CAA Record: Yes
- DNSBL Listed: 1 of 8 total lists
---
## Neighborhood Analysis
Subnet: 54.38.147.0/24
- Total Siblings: 256
- Active Siblings: 211
- Threat Siblings: 108
- Abuse Density: 0.4219 (moderate)
- Classification: Mixed
Risk Distribution in /24:
- High Risk: 0%
- Medium Risk: 75%
- Low Risk: 25%
The /24 subnet shows elevated abuse activity with 108 threat-sibling IPs identified. While the target IP (54.38.147.241) maintains a low-risk profile, analysts should monitor the subnet for potential lateral threat movement.
---
## Observation History
Total Observations: 23 signals
Recent Activity:
- 2026-06-27: Operator score 0.1, confidence 0.30
- 2026-06-26: Subnet abuse density 0.4219, confidence 0.75
- 2026-06-26: Cloud/hosting classification, confidence 0.85
- 2026-06-26: DNS resolution ahrefs.net, confidence 0.80
Temporal Analysis:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Is Persistently Malicious: No
- Threat Observation Count: 1
The IP demonstrates stable ownership characteristics with no persistent malicious behavior detected.
---
## Recommended Actions
Firewall/Security Recommendations: No specific actions required.
SOC Analyst Guidance:
1. Allow Traffic: The IP presents a low-risk profile with no active threat indicators
2. Monitor Subnet: Be aware that 54.38.147.0/24 has mixed classification with elevated abuse density
3. No Blocking Recommended: Current signals do not warrant blocking or rate-limiting
4. Correlation: 58 relationships identified, primarily to same network (OVH_282347341)
---
## Conclusion
IP 54.38.147.241 is a legitimate cloud infrastructure host associated with Ahrefs (SEO analytics platform). While the immediate IP presents no threat, the parent subnet shows moderate abuse activity. SOC teams should maintain contextual awareness of the /24 neighborhood without taking immediate defensive action against this specific IP.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk005-san241.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk005-san241.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 27% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-11 21:11:22 UTC |
| Last Seen | 2026-06-27 20:13:35 UTC |
| Profile Built | 2026-06-28 14:17:43 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 27 |
Full dossier details are available via our API.