IP Intelligence Briefing: 54.38.147.3/32
Executive Summary
The IP address 54.38.147.3 presents moderate risk (Score: 40) with operational characteristics consistent with cloud infrastructure hosting. The address resolved to a DNS entry associated with ahrefs.net and operates within OVH cloud infrastructure in London, UK.
Technical Profile
- Geolocation: England, London, GB (GeoPlausible: true)
- ASN: 16276 (OVH)
- Network Role: CloudCompute/Hosting infrastructure
- DNS: proxy-uk005-san3.ahrefs.net (ahrefs.net domain)
- Services: No open ports detected (firewalled/no services)
- Threat Indicators: No active threat indicators, zero blacklist entries at time of analysis
Risk Assessment
The address exhibits moderate risk classification driven primarily by neighborhood context rather than direct malicious activity. The /24 subnet (54.38.147.0/24) demonstrated elevated abuse density of 0.625 with 160 threat-sibling IPs among 193 active neighbors. However, the target IP itself showed no direct threat indicators, no known campaigns, and no persistent malicious behavior patterns.
Temporal Analysis
Observation history captured 25 signals over the monitoring period. Recent DNS resolution confirmed ahrefs.net ownership with proper CAA records. Geolocation validation showed 500.4km distance from claimed coordinates with 87-94ms RTT measurements. No ownership changes or threat persistence patterns observed.
Relationships
The IP maintains 64 relationship entries, predominantly network-level associations with OVH infrastructure identifier OVH_282347341.
Recommended Actions
Based on the moderate risk score and high-abuse neighborhood context, the following blocking rules are recommended:
```bash
# iptables
iptables -A INPUT -s 54.38.147.3 -j DROP
# nftables
nft add rule inet filter input ip saddr 54.38.147.3 drop
# nginx
deny 54.38.147.3;
# Cloudflare WAF
Expression: ip.src eq 54.38.147.3
```
Analyst Notes
While the IP lacks direct malicious indicators, the high-abuse density of its /24 subnet warrants consideration. The address operates as part of cloud hosting infrastructure with firewall protections in place. Monitor for any service changes or emerging threat indicators, though current data supports moderate-risk classification without immediate escalation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk005-san3.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk005-san3.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:28 UTC |
| Last Seen | 2026-06-27 07:54:10 UTC |
| Profile Built | 2026-06-28 01:59:47 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 27 |
Full dossier details are available via our API.