Your IP: 216.73.216.123
π€ Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.
IP Intelligence Briefing: 5.39.1.255
Date: 2026-06-08
---
**1. Core Profile**
- Risk Score: 40 (Moderate Risk)
- Ownership: Ahrefs Pte Ltd (OVH ASN 16276)
- Geolocation: France (FR), inferred via multi-signal analysis (latitude 46.23, longitude 2.21, ±500km accuracy).
- Network Role: CloudCompute instance (OVH infrastructure), hosting provider.
- Services: No open ports, no TLS certificates, no HTTP services detected.
---
**2. Threat Indicators**
- No direct malicious activity: No indicators of spam, attacks, or abuse detected.
- DNS Associations: Linked to `proxy-fr005-san255.ahrefs.net` (ahrefs.net domain).
- Subnet Risk: High abuse density (0.56) in the 5.39.1.255/24 subnet. Neighbors include 31 IPs, with 18 flagged as high-risk (β₯50 score).
---
**3. Historical Observations**
- Stability: Subnet and network role classifications have remained consistent since May 31, 2026.
- Geolocation: France inferred via multiple signals (e.g., RTT, DNS).
- Network Changes: No significant ownership or threat persistence detected.
---
**4. Relationships**
- Network: Same subnet as OVH network ID `OVH_282114230`.
- DNS: Strong association with `proxy-fr005-san255.ahrefs.net` (ahrefs.net).
- Certificates: CAA records detected, no TLS certificates observed.
---
**5. Neighborhood Analysis**
- Subnet: 5.39.1.255/24 (32 IPs total).
- Risky Neighbors: 18 IPs with β₯50 risk scores (e.g., 5.39.1.248 [65], 5.39.1.229 [65]).
- Abuse Density: 56.25% of subnet IPs flagged as high-risk.
---
**6. Recommendations**
- Monitor Subnet: The high abuse density in the subnet suggests potential for lateral movement or shared infrastructure risks.
- Verify DNS: Confirm legitimacy of `proxy-fr005-san255.ahrefs.net` as part of Ahrefs' infrastructure.
- Check Cloud Host: OVH hosting provider may require additional scrutiny for shared resource compromises.
- Block High-Risk Neighbors: Consider isolating or blocking neighboring IPs with elevated risk scores.
Note: This IP appears benign, but its subnetβs high-risk environment warrants closer monitoring.
---
*Generated by IPDebrief β Cybersecurity Threat Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | β |
| CIDR Block | β |
| RIR | RIPE |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | proxy-fr005-san255.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-fr005-san255.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
No certificate
Issued by β
N/A
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 16 |
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-19 03:36:36 UTC |
| Last Seen | 2026-06-28 08:30:06 UTC |
| Profile Built | 2026-06-29 02:35:09 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
π 22 signal types Β· 26 observations collected
This report is generated from 22+ independent intelligence signals including
ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds,
behavioral fingerprinting, and more.
Full dossier details are available via our API.
Full dossier details are available via our API.
βΉοΈ About This Report
All data shown is publicly available network metadata β IP addresses do not reliably identify individuals.
Assessments are probabilistic and should not be used as sole basis for access control decisions.
To report an issue or request data review, contact admin@ipdebrief.com.