# IP Intelligence Briefing: 5.39.109.177/32
Classification: Moderate Risk | Risk Score: 40 | Provider: OVH (ASN 16276)
## Executive Summary
IP 5.39.109.177 is a cloud hosting address owned by Ahrefs Pte Ltd Dmytro on the OVH infrastructure (ASN 16276). The IP is classified as cloud compute infrastructure with no active services detected (firewalled/no services). Despite the "Moderate Risk" classification and moderate risk score of 40, the IP shows no active threat indicators, is not on major threat feeds, and has zero blacklist hits. However, the IP is hosted in a high-abuse subnet (5.39.109.0/24) with an abuse density of 0.75 and 18 out of 24 sibling IPs flagged as threat sources.
## Technical Profile
Ownership & Routing:
- ASN: 16276 (OVH)
- BGP Prefix: 5.39.0.0/17
- RIR: RIPE
- DNSSEC Valid: Yes
- Has CAA: Yes
- Route Stability: Stable (0 route changes in 30 days)
Geolocation:
- Country: France (FR)
- Region: US-NY (reported)
- Accuracy: ±500km
- Average RTT: 90.8ms
- GeoPlausible: Yes
Network Role:
- Infrastructure Type: CloudCompute
- Is Cloud: Yes
- Is Hosting: Yes
- Connection Type: Firewalled / No Services
- No open ports detected
DNS Resolution:
- PTR Hostname: proxy-fr009-san177.ahrefs.net
- Forward Resolution: proxy-fr009-san177.ahrefs.net
- Forward Confirmed: No
- Domain: ahrefs.net
## Threat Assessment
Threat Indicators:
- Abuse Confidence Score: Not reported
- Is Tor Exit: No
- Is Known Attacker: No
- Is Spam Source: No
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 lists
- Known Campaigns: None
Behavioral Signals:
- Honeypot Hits: 0
- Threat Persistence Days: 0
- Persistently Malicious: No
- Campaign Likelihood: None
Control Plane:
- Operator Score: 0.2174 (Minimal)
- Route Changes 30d: 0
- Is Route Stable: Yes
- Is MoAS: No
## Neighborhood Analysis
Subnet: 5.39.109.0/24
| Metric | Value |
|---|---|
| Total Siblings | 24 |
| Active Siblings | 14 |
| Threat Siblings | 18 |
| Abuse Density | 0.75 (High) |
| Inherited Risk | 30 |
| Classification | High Abuse |
Risk Distribution in Subnet:
- High Risk: 0 IPs
- Medium Risk: 9 IPs
- Low Risk: 14 IPs
Multiple neighbors (5.39.109.160, .162, .166, .167, .168, .170, .171, .176, .178, .180, .187, .189, .190) show elevated risk scores of 40.
## Observation History
The IP has 21 recorded observations. Recent signals (as of 2026-06-26) indicate:
- OVH cloud hosting infrastructure
- France-based geolocation with 52% confidence
- ahrefs.net domain resolution
- Minimal operator score
- 20% overall confidence on comprehensive signal assessment
## Relationship Graph
51 relationships detected, primarily tied to the same network (OVH_282114234). The IP is associated with multiple entities sharing the same network infrastructure.
## Recommended Actions
Based on the risk profile, the following firewall rules are recommended:
iptables:
```bash
iptables -A INPUT -s 5.39.109.177 -j DROP
```
nftables:
```bash
nft add rule inet filter input ip saddr 5.39.109.177 drop
```
nginx:
```nginx
deny 5.39.109.177;
```
pfSense:
```
5.39.109.177/32
```
Cloudflare WAF:
```json
{
"description": "Block 5.39.109.177 โ IPDebrief risk score 40",
"action": "block",
"filter": {
"expression": "ip.src eq 5.39.109.177"
}
}
```
AWS WAF:
```json
{
"Addresses": ["5.39.109.177/32"],
"Description": "IPDebrief risk 40"
}
```
## Intelligence Narrative
IP 5.39.109.177 represents a legitimate cloud hosting resource within a high-abuse subnet. While the IP itself shows no active malicious behavior, the surrounding neighborhood (5.39.109.0/24) exhibits significant abuse activity with an abuse density of 0.75. The IP is associated with Ahrefs infrastructure but presents a moderate risk profile due to its hosting environment and proximity to known abuse sources.
Recommended posture: Apply blocking rules at the perimeter layer but monitor for legitimate traffic patterns. The IP's association with ahrefs.net suggests potential legitimate use, yet the high-abuse subnet context warrants defensive blocking. Consider implementing rate limiting or time-based restrictions if the IP is observed in legitimate traffic flows.
Priority: Medium โ Block due to
Medium โ Block due to high-abuse neighborhood context despite individual IP showing no active threat indicators. Monitor for legitimate Ahrefs-related traffic that may be inadvertently blocked.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-fr009-san177.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-fr009-san177.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 17% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 31% | 2 | 3 |
| Overall | 21% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-10 22:17:47 UTC |
| Last Seen | 2026-06-27 18:34:27 UTC |
| Profile Built | 2026-06-28 12:39:15 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 26 |
Full dossier details are available via our API.