# IP Intelligence Briefing: 54.38.147.57/32
Classification: Moderate Risk
Date: 2026-06-28
Analyst: IPDebrief Intelligence Division
## Executive Summary
IP address 54.38.147.57 is associated with OVH cloud infrastructure in London, England (GB). The IP demonstrates moderate risk characteristics with no active threat indicators but exhibits elevated neighborhood abuse density. The address is classified under the ahrefs.net domain infrastructure, hosted on OVH cloud compute services.
## Technical Profile
- ASN: 16276 (OVH)
- Organization: Ahrefs Pte Ltd Dmytro
- Geolocation: London, England, GB (750km accuracy radius)
- Infrastructure Type: Cloud Compute (OVH)
- DNS Resolution: proxy-uk005-san57.ahrefs.net
- Network Role: Hosting/Cloud (Firewalled/No Services)
- Risk Score: 50/100 (Moderate)
## Threat Indicators
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Status: Listed on 2 of 8 DNSBLs
- Threat Campaigns: None identified
- Open Ports: None detected (firewalled)
- TLS/HTTP Services: None active
## Neighborhood Analysis (54.38.147.0/24)
- Subnet Abuse Density: 0.6875 (High)
- Active Siblings: 210 out of 256 total IPs
- Threat Siblings: 176 IPs flagged as threats
- Inherited Risk: 27/100
- Risk Distribution: 0 High, 19 Medium, 81 Low risk neighbors
## Historical Observation (22 Signals)
The IP has maintained consistent classification patterns over the observation period:
- Recent signals (June 2026) confirm cloud compute infrastructure classification
- Abuse density signal maintained at 0.6875 across multiple observations
- DNS blacklist listings persisted across observation windows
- Geographic location consistently inferred as GB region
## Relationship Mapping
49 relationships identified, primarily same-network associations within OVH infrastructure (OVH_282347341). No certificate or hostname relationships beyond the ahrefs.net domain.
## Recommended Actions
1. Monitor but do not block: The IP shows moderate risk with no active malicious indicators
2. Monitor DNSBL listings: Track the 2 active blacklist associations for changes
3. Subnet awareness: The /24 subnet shows high abuse densityβcorrelate any suspicious activity with neighboring IPs
4. Service validation: No open ports detected; verify if services are legitimately firewalled or misconfigured
## SOC Analyst Notes
This IP represents legitimate cloud hosting infrastructure (OVH) associated with Ahrefs, a legitimate SEO analytics provider. The moderate risk score derives from neighborhood abuse patterns rather than direct threat indicators. While the subnet shows elevated abuse density, this specific IP has no active threat signatures. Recommend continued monitoring without immediate blocking actions.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | proxy-uk005-san57.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk005-san57.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 26% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-22 03:10:27 UTC |
| Last Seen | 2026-06-28 17:56:25 UTC |
| Profile Built | 2026-06-29 05:58:40 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.