IPDebrief

54.38.147.67

IP Intelligence Dossier
Your IP: 216.73.217.135
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IPDEBRIEF INTELLIGENCE BRIEFING

Target IP: 54.38.147.67/32

Date: 2026-06-15

Classification: LOW RISK / LEGITIMATE INFRASTRUCTURE

---

## EXECUTIVE SUMMARY

IP 54.38.147.67 operates within legitimate cloud infrastructure belonging to Ahrefs Pte Ltd Dmytro (ASN 16276). The address maintains a Low Risk reputation score of 25 and demonstrates no active threat indicators. Current assessment indicates this is a legitimate proxy infrastructure component for ahrefs.net with no evidence of malicious activity.

---

## OWNERSHIP AND GEOLOCATION

The IP address resolves to Ahrefs Pte Ltd Dmytro, registered under AS16276 in the ARIN RIR. Geolocation data consistently places the endpoint in London, England (GB), with timezone Europe/London. The endpoint operates within the 54.38.0.0/16 BGP prefix with origin ASN 16276. Infrastructure classification identifies the address as cloud-based hosting infrastructure (OVH provider) with no CDN, VPN, or proxy designation despite hostname patterns suggesting proxy functionality.

---

## NETWORK INFRASTRUCTURE ANALYSIS

The endpoint resides within the 54.38.147.0/24 subnet, which exhibits mixed classification characteristics with 256 total sibling addresses, 124 active siblings, and 120 threat siblings. The subnet demonstrates an abuse density of 0.4688, with risk distribution showing zero high-risk addresses, 95 medium-risk addresses, and 5 low-risk addresses. The target IP itself carries an inherited risk score of 18 from neighborhood context.

The /24 subnet shows moderate abuse activity with neighbor risk scores ranging from 40-50 for sampled endpoints. However, the target IP maintains a risk score of 25, positioning it below the neighborhood median.

---

## DNS AND SERVICE ANALYSIS

DNS resolution confirms the address resolves to proxy-uk005-san67.ahrefs.net within the ahrefs.net domain. Forward DNS confirmation is present with 1 forward resolution record. The endpoint shows no open ports during service scanning, classified as "Firewalled / No Services." TLS certificate and HTTP title data remain null, indicating service restrictions consistent with proxy infrastructure behavior.

DNS security posture shows DNSSEC validation enabled and CAA records present. The domain maintains operational DNS infrastructure with 1 issuer and multiple CAA records.

---

## THREAT INDICATORS

Threat intelligence analysis returned no active indicators. The endpoint is not identified as:

Blacklist analysis showed zero blacklist matches and one DNSBL listing (dnsblListedCount: 1). Pulsedive risk scoring and known campaign correlations returned null values. No threat feeds flagged the address.

---

## OBSERVATION HISTORY

Eighteen signal observations recorded between June 2026 show consistent operational patterns. Recent observations (2026-06-15) maintained operator scores of 0.2174 (Minimal). DNS associations with ahrefs.net remained consistent across observations. Subnet abuse density measurements stabilized at 0.4688. No ownership changes or persistent malicious activity detected.

---

## SECURITY RECOMMENDATIONS

Based on current risk profile assessment, no immediate blocking or filtering actions required. The endpoint demonstrates legitimate infrastructure characteristics with no active threat behavior. SOC teams may monitor the associated subnet (54.38.147.0/24) for broader context, as 120 threat siblings exist within the neighborhood.

Recommended actions:

---

Report Generated: IPDebrief Intelligence Platform

Analysis Type: Defensive Security Intelligence

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom
RegionEngland
CityLondon
TimezoneEurope/London
Latitude48.86
Longitude2.34

๐Ÿข Ownership & Registration

OrganizationAhrefs Pte Ltd Dmytro
ASNAS16276
Network Nameโ€”
CIDR Blockโ€”
RIRARIN
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRproxy-uk005-san67.ahrefs.net
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-uk005-san67.ahrefs.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
39%
23
routing
13%
11
services
15%
22
ownership
20%
23
reputation
22%
12
geolocation
33%
23
Overall24%1014
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-18 03:23:27 UTC
Last Seen2026-06-28 06:47:58 UTC
Profile Built2026-06-29 00:53:33 UTC
Data FreshnessLive
Signal Types20
Total Observations23
๐Ÿ” 20 signal types ยท 23 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.