# IP Intelligence Briefing: 54.38.147.80/32
## Executive Summary
IP 54.38.147.80 is a cloud compute address assigned to OVH infrastructure with moderate risk scoring (40/100). While the specific IP shows no direct malicious indicators, it resides within a high-abuse density subnet (66%), suggesting contextual risk from neighboring addresses. The IP resolves to legitimate ahrefs.net infrastructure, indicating potential shared hosting environment.
## Technical Profile
- IP Address: 54.38.147.80/32
- ASN: 16276 (OVH)
- Organization: Ahrefs Pte Ltd Dmytro
- Location: London, England, GB (55.38°N, -3.44°W)
- Infrastructure Type: Cloud Compute
- DNS: proxy-uk005-san80.ahrefs.net โ ahrefs.net
- Network Role: Firewalled / No Services detected
- Risk Score: 40 (Moderate Risk)
- DNSBL Status: Listed on 1 of 8 threat feeds
## Neighborhood Assessment
The /24 subnet (54.38.147.0/24) exhibits elevated abuse activity:
- Active Siblings: 193/256
- Abuse Density: 0.6602 (66%)
- Threat Siblings: 169
- Risk Distribution: 0 high-risk, 62 medium-risk, 38 low-risk IPs
- Inherited Risk Score: 26
The subnet classification as "high_abuse" indicates this IP block is frequently utilized for potentially malicious activities by neighboring addresses, though this specific IP lacks direct threat indicators.
## Historical Analysis
Signal history reveals:
- No persistent malicious activity detected (threat observation count: 0)
- Not classified as persistently malicious
- Recent subnet classification consistently shows high_abuse density
- Operator score: 0.2174 (Minimal)
- Route stability: Unstable (isRouteStable: false)
- Geo validation: Plausible, minimum RTT 96ms
## Relationships
- 37 relationship links identified
- All links correspond to OVH network (OVH_282347341)
- No external associations to organizations, hostnames, or certificates beyond network-level infrastructure
## Recommended Actions
Based on risk profile and neighborhood context, the following firewall rules are recommended:
iptables:
```bash
iptables -A INPUT -s 54.38.147.80 -j DROP
```
nftables:
```bash
nft add rule inet filter input ip saddr 54.38.147.80 drop
```
AWS WAF:
```json
{
"Addresses": ["54.38.147.80/32"],
"Description": "IPDebrief risk 40"
}
```
## Intelligence Assessment
This IP represents a moderate-risk address within a high-abuse density cloud infrastructure environment. The IP resolves to legitimate ahrefs.net infrastructure but operates in a subnet with 66% abuse density, suggesting shared hosting or compromised neighboring addresses. While no direct attack indicators were observed, the neighborhood context warrants monitoring. SOC teams should evaluate whether blocking is appropriate based on organizational risk tolerance and whether the IP is being used as an entry point for lateral movement from compromised neighbors.
Classification: Moderate Risk / Contextual Threat
Confidence Level: 0.24 (Low)
Threat Persistence: None Detected
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk005-san80.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk005-san80.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 03:23:27 UTC |
| Last Seen | 2026-06-28 06:48:52 UTC |
| Profile Built | 2026-06-29 00:53:32 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.