IPDebrief

54.39.0.146

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target: 54.39.0.146/32

Date: 2026-06-20

Classification: Moderate Risk

---

## EXECUTIVE SUMMARY

IP 54.39.0.146 is a cloud-hosted infrastructure address associated with OVH Canada (ASN 16276) and the organization "Dmytro, Ahrefs Pte Ltd." The IP carries a risk score of 40 (Moderate Risk) and resides within a high-abuse density subnet (54.39.0.0/24) with an abuse density of 0.7188. No direct threat indicators or blacklistings were observed. Geolocation data shows validation inconsistencies requiring attention.

---

## OWNERSHIP & INFRASTRUCTURE

FieldValue
**ASN**16276 (OVH)
**Organization**Dmytro, Ahrefs Pte Ltd
**CIDR Block**54.39.0.0/24
**Registration**RIR: ARIN
**Infrastructure Type**Cloud Compute / Hosting
**Country**Canada (QC, Beauharnois)
**PTR Record**proxy-ca004-san146.ahrefs.net
**Domain**ahrefs.net

The IP is classified as cloud-hosted infrastructure with no detected open ports, services, or active web presence. Forward DNS resolution confirmed a single PTR record pointing to a proxy hostname.

---

## RISK ASSESSMENT

MetricScoreAssessment
**Overall Risk**40Moderate Risk
**Abuse Confidence**N/ANot available
**Blacklist Count**0Not blacklisted
**Known Attacker**FalseNo indicators
**Tor Exit/Proxy**FalseNot identified
**Threat Persistence**0 daysNo persistent threats
**Control Plane Risk**0.2174Minimal

Threat Indicators: None detected. No known campaigns, threat feeds, or abuse indicators associated with this IP.

---

## NEIGHBORHOOD ANALYSIS (54.39.0.0/24)

The /24 subnet shows elevated abuse activity:

MetricValue
**Total Siblings**256
**Active Siblings**227
**Threat Siblings**184
**Abuse Density**0.7188
**Subnet Classification**High Abuse
**Inherited Risk**28

Risk distribution across the subnet:

The neighborhood context suggests this subnet hosts a mix of legitimate and potentially abused cloud resources, typical of large OVH hosting environments.

---

## OBSERVATION HISTORY

Total Observations: 20 (Latest: 2026-06-20 15:55 UTC)

Key historical signals:

Geolocation Validation Issue: The geolocation data shows a 5,629km distance discrepancy with an RTT of 28ms, which is below the minimum physically possible RTT of 112.6ms. This suggests inaccurate or spoofed geolocation data.

---

## RELATIONSHIP GRAPH

Total Relationships: 47

Primary relationship types:

The IP is primarily linked to network-level entities within the OVH cloud infrastructure. No significant associations with organizations, hostnames, or certificates beyond the PTR record.

---

## RECOMMENDED ACTIONS

Based on risk profile (Score: 40), the following security controls are recommended:

Firewall Rules

PlatformRule
**iptables**`iptables -A INPUT -s 54.39.0.146 -j DROP`
**nftables**`nft add rule inet filter input ip saddr 54.39.0.146 drop`
**nginx**`deny 54.39.0.146;`
**pfSense**`54.39.0.146/32`
**Cloudflare WAF**Block with expression: `ip.src eq 54.39.0.146`
**AWS WAF**`{"Addresses":["54.39.0.146/32"], "Description":"IPDebrief risk 40"}`

---

## INTELLIGENCE NARRATIVE FOR SOC ANALYSTS

IP 54.39.0.146 represents a moderate-risk cloud-hosted address within the OVH Canada infrastructure. The IP's PTR record indicates association with a proxy hostname under the ahrefs.net domain. While no direct threat indicators or blacklistings are present, the subnet (54.39.0.0/24) exhibits elevated abuse density (0.7188) with 184 threat-sibling IPs out of 227 active siblings.

The geolocation data requires scrutinyβ€”the reported location (Beauharnois, QC, Canada) is geographically inconsistent with observed RTT measurements, suggesting potential data spoofing or routing anomalies.

Recommendation: Monitor inbound traffic from this IP for suspicious patterns. The moderate risk score and high-abuse neighborhood context warrant defensive blocking at perimeter controls while avoiding aggressive response without additional context. Consider blocklisting the /24 subnet if lateral movement or coordinated abuse is observed from neighboring IPs

---

## CONCLUSION

This IP represents a defensive priority case due to the combination of moderate risk score, high-abuse neighborhood context, and geolocation validation inconsistencies. While no active threat indicators are currently present, the subnet-level abuse density suggests this IP may be utilized for various non-malicious purposes (e.g., web scraping, hosting, or proxy services) that could intersect with organizational security boundaries.

Priority Level: Monitor

Recommended Action: Implement blocklist rules at perimeter controls; correlate with additional threat feeds before escalating to incident response

---

Document Classification: Internal Use Only

Generated By: IPDebrief Threat Intelligence Platform

Review Period: 2026-06-20 (Rolling 30-Day)

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡¨πŸ‡¦ Canada
RegionQC
CityBeauharnois
Timezoneβ€”
Latitude45.32
Longitude-73.87

🏒 Ownership & Registration

OrganizationDmytro, Ahrefs Pte Ltd
ASNAS16276
Network NameOVH-CUST-281059683
CIDR Block54.39.0.0/24
RIRARIN
CountrySingapore
Abuse Contactβ€”

🌐 DNS Intelligence

PTRproxy-ca004-san146.ahrefs.net
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-ca004-san146.ahrefs.net

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
29%
24
routing
13%
11
services
15%
22
ownership
15%
22
reputation
28%
13
geolocation
39%
23
Overall23%1015
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-22 03:10:28 UTC
Last Seen2026-06-28 17:57:46 UTC
Profile Built2026-06-29 06:00:58 UTC
Data FreshnessLive
Signal Types21
Total Observations25
πŸ” 21 signal types Β· 25 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.