# IP INTELLIGENCE BRIEFING: 54.38.147.71
## Executive Summary
IP 54.38.147.71 is a moderate-risk cloud infrastructure endpoint associated with ahrefs.net, hosted on OVH network infrastructure in London, UK. The IP shows no active open services but resides within a high-abuse-density subnet (0.5195 abuse density), indicating elevated neighborhood risk despite the endpoint's own risk score of 40.
## Technical Profile
- IP Address: 54.38.147.71/32
- Risk Score: 40 (Moderate Risk)
- ASN: AS16276 (OVH SAS)
- Organization: Ahrefs Pte Ltd Dmytro
- Geolocation: London, England, GB (Europe/London timezone)
- Infrastructure Type: CloudCompute/Hosting
- DNS Resolves: proxy-uk005-san71.ahrefs.net
- Network Range: 54.38.0.0/16 (OVH BGP)
- Service Status: Firewalled/No Services Detected
## Neighborhood Analysis
The /24 subnet (54.38.147.0/24) exhibits high abuse classification with 133 threat siblings among 256 active addresses (51.95% abuse density). All 100 sampled neighbors returned medium-risk scores (40-50 range). The subnet's high abuse density warrants heightened monitoring despite this specific IP's moderate risk rating.
## Relationship Graph
- Network Association: OVH_282347341 (cloud infrastructure)
- DNS Association: proxy-uk005-san71.ahrefs.net (multiple records)
- Control Plane: AS34549 โ AS16276 (OVH)
- Route Stability: Stable (0 route changes in 30 days)
## Observation History
27 historical observations recorded. Recent signals (June 2026) indicate:
- ASN routing signals for AS16276 (OVH SAS)
- Route stability confirmed
- Multiple threat feed correlations
- Basic infrastructure signals with 85% confidence
## Threat Indicators
- Blacklist Count: 0
- Is Known Attacker: No
- Is Spam Source: No
- Tor Exit: No
- Active Threats: None detected
- Campaign Correlation: None
## Recommended Actions
Given the moderate risk profile but high-abuse neighborhood context:
1. Monitor: Enable logging for traffic from 54.38.147.0/24 subnet
2. Allow: Traffic may be legitimate (ahrefs.net infrastructure)
3. Block: No immediate blocking required based on current profile
4. Review: Monitor for behavioral changes indicating abuse escalation
## Intelligence Assessment
The IP represents legitimate cloud infrastructure hosting ahrefs.net services. While the endpoint itself is not actively malicious, the surrounding subnet shows concentrated abuse activity. Recommend continued monitoring and correlation with any observed malicious behavior rather than immediate blocking.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | 54.38.0.0/16 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk005-san71.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk005-san71.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 39% | 2 | 3 |
| routing | 27% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 24% | 3 | 4 |
| reputation | 22% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 26% | 12 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 21:40:50 UTC |
| Last Seen | 2026-06-28 10:21:26 UTC |
| Profile Built | 2026-06-29 04:25:56 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 28 |
Full dossier details are available via our API.