# IPDEBRIEF INTELLIGENCE BRIEFING
Target IP: 54.38.147.67/32
Date: 2026-06-15
Classification: LOW RISK / LEGITIMATE INFRASTRUCTURE
---
## EXECUTIVE SUMMARY
IP 54.38.147.67 operates within legitimate cloud infrastructure belonging to Ahrefs Pte Ltd Dmytro (ASN 16276). The address maintains a Low Risk reputation score of 25 and demonstrates no active threat indicators. Current assessment indicates this is a legitimate proxy infrastructure component for ahrefs.net with no evidence of malicious activity.
---
## OWNERSHIP AND GEOLOCATION
The IP address resolves to Ahrefs Pte Ltd Dmytro, registered under AS16276 in the ARIN RIR. Geolocation data consistently places the endpoint in London, England (GB), with timezone Europe/London. The endpoint operates within the 54.38.0.0/16 BGP prefix with origin ASN 16276. Infrastructure classification identifies the address as cloud-based hosting infrastructure (OVH provider) with no CDN, VPN, or proxy designation despite hostname patterns suggesting proxy functionality.
---
## NETWORK INFRASTRUCTURE ANALYSIS
The endpoint resides within the 54.38.147.0/24 subnet, which exhibits mixed classification characteristics with 256 total sibling addresses, 124 active siblings, and 120 threat siblings. The subnet demonstrates an abuse density of 0.4688, with risk distribution showing zero high-risk addresses, 95 medium-risk addresses, and 5 low-risk addresses. The target IP itself carries an inherited risk score of 18 from neighborhood context.
The /24 subnet shows moderate abuse activity with neighbor risk scores ranging from 40-50 for sampled endpoints. However, the target IP maintains a risk score of 25, positioning it below the neighborhood median.
---
## DNS AND SERVICE ANALYSIS
DNS resolution confirms the address resolves to proxy-uk005-san67.ahrefs.net within the ahrefs.net domain. Forward DNS confirmation is present with 1 forward resolution record. The endpoint shows no open ports during service scanning, classified as "Firewalled / No Services." TLS certificate and HTTP title data remain null, indicating service restrictions consistent with proxy infrastructure behavior.
DNS security posture shows DNSSEC validation enabled and CAA records present. The domain maintains operational DNS infrastructure with 1 issuer and multiple CAA records.
---
## THREAT INDICATORS
Threat intelligence analysis returned no active indicators. The endpoint is not identified as:
- Known attacker
- Spam source
- Tor exit node
Blacklist analysis showed zero blacklist matches and one DNSBL listing (dnsblListedCount: 1). Pulsedive risk scoring and known campaign correlations returned null values. No threat feeds flagged the address.
---
## OBSERVATION HISTORY
Eighteen signal observations recorded between June 2026 show consistent operational patterns. Recent observations (2026-06-15) maintained operator scores of 0.2174 (Minimal). DNS associations with ahrefs.net remained consistent across observations. Subnet abuse density measurements stabilized at 0.4688. No ownership changes or persistent malicious activity detected.
---
## SECURITY RECOMMENDATIONS
Based on current risk profile assessment, no immediate blocking or filtering actions required. The endpoint demonstrates legitimate infrastructure characteristics with no active threat behavior. SOC teams may monitor the associated subnet (54.38.147.0/24) for broader context, as 120 threat siblings exist within the neighborhood.
Recommended actions:
- Monitor subnet-level activity patterns for correlation
- Allow traffic from this IP; no firewall rules necessary
- Maintain awareness of associated domain: ahrefs.net
---
Report Generated: IPDebrief Intelligence Platform
Analysis Type: Defensive Security Intelligence
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk005-san67.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk005-san67.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 39% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 03:23:27 UTC |
| Last Seen | 2026-06-28 06:47:58 UTC |
| Profile Built | 2026-06-29 00:53:33 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.