IP Intelligence Briefing: 5.39.109.189
Date: 2026-06-01
---
**1. Core Profile**
- Risk Score: 40 (Moderate Risk)
- Ownership:
- ASN: 16276 (OVH)
- Organization: Ahrefs Pte Ltd Dmytro
- Network: OVH_282114234 (5.39.109.160/27)
- Geolocation:
- Country: France (FR)
- City: Singapore (likely misattributed or inferred)
- Timezone: Europe/Paris
- Accuracy Radius: 500 km
- Threat Indicators:
- No direct malicious indicators (no blacklists, campaigns, or spam).
- Subnet Abuse Density: 70.83% (high abuse classification).
- Neighbor Risk: 28 inherited risk score from subnet.
---
**2. Network Behavior**
- Infrastructure:
- Cloud Compute: Hosted by OVH (cloud provider).
- Services: No open ports or TLS certificates detected.
- Subnet Analysis:
- /24 Subnet: 5.39.109.189/24
- Total Siblings: 24 IPs | Active Siblings: 5 | Threat Siblings: 17
- Abuse Density: 70.83% (high risk).
- Neighbors: 23 IPs in subnet, most with risk scores β₯40.
---
**3. Historical Observations**
- Recent Activity (2026-06-01):
- No persistent threats or malicious behavior.
- Threat Persistence: 0 days | Threat Observations: 0.
- Stability: Unstable routing (route changes detected).
- Geolocation Inference: Confirmed as France (FR) with 500 km accuracy.
---
**4. Relationships & Dependencies**
- DNS Associations:
- Resolves to `proxy-fr009-san189.ahrefs.net` (Ahrefs Pte Ltd).
- Network Links:
- Part of OVHβs 5.39.109.160/27 subnet.
- BGP Prefix: 5.39.0.0/17 (OVH).
- Operator Risk Score: 0.2174 (Minimal).
---
**5. Recommendations**
- Monitor Subnet: High abuse density in 5.39.109.189/24 warrants closer scrutiny.
- Check Hostname: Investigate `proxy-fr009-san189.ahrefs.net` for potential misuse.
- Firewall Actions: Consider blocking or rate-limiting traffic from this subnet if suspicious activity is detected.
- Geolocation Verification: Validate the "Singapore" city attribution, as it conflicts with the French ISP (OVH).
---
Conclusion:
This IP is part of a high-risk subnet associated with OVHβs cloud infrastructure. While no direct malicious activity is detected, the subnetβs abuse density and inferred geolocation anomalies suggest potential operational risks. SOC teams should prioritize monitoring this subnet for unusual behavior.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | OVH_282114234 |
| CIDR Block | 5.39.109.160/27 |
| RIR | RIPE |
| Country | FR |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | proxy-fr009-san189.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-fr009-san189.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 24% | 2 | 3 |
| Overall | 20% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-29 18:15:16 UTC |
| Last Seen | 2026-06-29 06:45:46 UTC |
| Profile Built | 2026-06-29 06:57:36 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.