## IP Intelligence Briefing: 54.39.0.105/32
Executive Summary
IP address 54.39.0.105 is a cloud-hosted address owned by Dmytro, Ahrefs Pte Ltd, operating on OVH infrastructure (AS16276). The IP carries a moderate risk score of 40 and is classified as high-abuse within its subnet. No active threat indicators were observed, but the subnet's abuse density warrants monitoring.
Profile Details
- Risk Score: 40 (Moderate Risk)
- Organization: Dmytro, Ahrefs Pte Ltd
- ASN: 16276 (OVH)
- Network Block: 54.39.0.0/16
- Geolocation: Beauharnois, QC, CA (geolocation validation failedβRTT 26ms inconsistent with 5,629km claimed distance)
- Infrastructure Type: CloudCompute/Hosting
- Network Role: Firewalled / No Services Detected
DNS and Hostname Intelligence
- PTR Record: proxy-ca004-san105.ahrefs.net
- Domain Association: ahrefs.net
- Forward Resolution: 1 hostname
- Email Authentication: No SPF or DMARC records configured
Neighborhood Analysis
The /24 subnet (54.39.0.0/24) shows elevated abuse characteristics:
- Abuse Density: 0.6953 (high classification)
- Active Siblings: 220 of 256 total IPs
- Threat Siblings: 178 IPs flagged as threats
- Neighbor Risk Distribution: 98 medium-risk, 2 low-risk, 0 high-risk IPs
Historical Observations
26 observations recorded over the analysis period. Signals include:
- Consistent geolocation anomalies (RTT violations)
- Persistent hosting classification
- No significant risk escalation trends
- Average ownership duration insufficient to establish persistence patterns
Threat Indicators
- Known Campaigns: None
- Blacklist Count: 0
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Pulsedive Risk: Not assessed
Recommended Security Actions
Based on risk profile, the following firewall rules are recommended:
iptables: `iptables -A INPUT -s 54.39.0.105 -j DROP`
nftables: `nft add rule inet filter input ip saddr 54.39.0.105 drop`
nginx: `deny 54.39.0.105;`
Cloudflare WAF: Block expression `ip.src eq 54.39.0.105`
AWS WAF: Address `54.39.0.105/32`
Intelligence Notes
The IP is associated with the ahrefs.net domain namespace but shows no open services. The high abuse density of the parent subnet (0.6953) combined with 178 threat siblings suggests this /24 may be compromised or misused. While no active threat indicators were observed, the moderate risk score and neighborhood context warrant defensive blocking. The geolocation discrepancy (RTT violation) indicates potential spoofing or misrepresentation.
Classification: Moderate Risk / Monitor
Confidence Level: Medium (geolocation validation failed)
Recommended Action: Block with logging enabled
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059683 |
| CIDR Block | 54.39.0.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca004-san105.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca004-san105.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 20% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:28 UTC |
| Last Seen | 2026-06-27 07:55:50 UTC |
| Profile Built | 2026-06-28 02:00:58 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 29 |
Full dossier details are available via our API.