# IP Intelligence Briefing: 54.38.94.109/32
Classification: Moderate Risk
Generated: 2026-06-19
## Executive Summary
IP 54.38.94.109 is a French-origin cloud compute host operated by OVH SAS (AS16276) with an overall risk score of 65/100. The IP exhibits moderate risk characteristics including DNSBL listings, RDP service exposure, and association with network infrastructure. Recommended action is monitoring with potential blocking depending on observed behavior patterns.
---
## Ownership & Infrastructure
| Attribute | Value |
|---|---|
| **Organization** | OVH SAS |
| **ASN** | AS16276 |
| **Country** | France (FR) |
| **Infrastructure Type** | CloudCompute |
| **CIDR Block** | 54.38.94.0/24 |
| **Registration** | ARIN |
---
## Network Classification
- Provider: OVH (Cloud hosting infrastructure)
- Connection Type: Single-Service Host
- Cloud Environment: Yes
- Cdn/VPN/Proxy: No
- Hosting Service: Yes
---
## Threat Indicators
| Indicator | Status |
|---|---|
| **Risk Score** | 65/100 (Moderate) |
| **DNSBL Listings** | 2 of 8 total lists |
| **Tor Exit Node** | No |
| **Known Attacker** | No |
| **Spam Source** | No |
| **Abuse Confidence** | Not rated |
---
## Technical Services & Ports
- Open Port 3389/TCP: RDP (Remote Desktop Protocol)
- DNS PTR: ns3140875.ip-54-38-94.eu
- DNS Forward Resolution: Confirmed
- TLS Certificate: Not detected
- HTTP Banner: No response
---
## Historical Observations (22 Total)
Recent signal history indicates:
- Multiple DNSBL listing detections (high severity)
- Geolocation inference pointing to France (500km accuracy radius)
- ASN attribution confirmed as OVH SAS
- Routing and ownership signals observed across 6 dimensions
- 3 out of 8 DNSBL lists flagged with high severity
---
## Network Neighborhood Analysis
- Subnet: 54.38.94.0/24
- Abuse Density: 1 (classified as mostly_clean)
- Sibling IPs: 1 active
- Threat Siblings: 1
---
## Related Entities (43 Relationships)
Key associations include:
- DNS Hostnames: ns3140875.ip-54-38-94.eu
- Network Identifiers: SD-1G-SBG3 (multiple references)
---
## Recommended Security Actions
Priority: High
Action: Increase monitoring and review recent activity from this IP due to elevated risk score (65/100)
Firewall Rules
iptables:
```
iptables -A INPUT -s 54.38.94.109 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 54.38.94.109 drop
```
nginx:
```
deny 54.38.94.109;
```
Cloudflare WAF:
```json
{
"description": "Block 54.38.94.109 โ IPDebrief risk score 65",
"action": "block",
"filter": {
"expression": "ip.src eq 54.38.94.109"
}
}
```
AWS WAF:
```json
{
"Addresses": ["54.38.94.109/32"],
"Description": "IPDebrief risk 65"
}
```
---
## Analyst Notes
- RDP service exposure on port 3389 warrants attention for potential unauthorized access attempts
- Multiple DNSBL listings suggest reputation degradation
- Cloud hosting environment with moderate risk profile
- No evidence of active campaign correlation
- Consider blocking if no legitimate business relationship exists
---
Status: Monitoring Recommended
Confidence: Moderate
Source: IPDebrief Intelligence Platform
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH SAS |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ns3140875.ip-54-38-94.eu |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ns3140875.ip-54-38-94.eu |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | โ |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 37% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-09 11:34:10 UTC |
| Last Seen | 2026-06-27 15:47:17 UTC |
| Profile Built | 2026-06-28 09:52:02 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 28 |
Full dossier details are available via our API.