# IP Intelligence Briefing: 54.39.0.171/32
Classification: LOW RISK | Last Updated: 2026-06-27
---
## Executive Summary
IP address 54.39.0.171 is a low-risk residential proxy endpoint associated with OVH cloud infrastructure in Beauharnois, Quebec, Canada. The IP belongs to Ahrefs Pte Ltd (ASN 16276) and resolves to proxy-ca004-san171.ahrefs.net. No active threat indicators, blacklist entries, or malicious campaign associations detected.
---
## Risk Profile
- Risk Score: 25/100 (Low Risk)
- Reputation: Low Risk
- Abuse Confidence Score: Not available
- Provider Score: 0/100
- Authority Score: 0/100
- Stability: Not established
---
## Network Classification
- Infrastructure Type: Cloud Compute / Hosting
- ISP/Provider: OVH
- Network Block: 54.39.0.0/16
- Organization: Dmytro, Ahrefs Pte Ltd
- Registration: ARIN
- CIDR Block: 54.39.0.0/24
---
## Geolocation
- Country: Canada (CA)
- Region: Quebec (QC)
- City: Beauharnois
- Location Accuracy: 3,000 km radius
- DNS Resolution: proxy-ca004-san171.ahrefs.net โ ahrefs.net
---
## Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- Threat Feeds: None
- Known Campaigns: None
---
## Service Analysis
- Open Ports: None detected
- TLS Certificate: No certificate found
- HTTP Title: No response captured
- Server Banner: None
- Connection Status: Firewalled / No Services
---
## Observations History
- Total Observations: 26 signals
- Latest Observation: 2026-06-27
- Threat Persistence Days: 0
- Ownership Changes: 0
- Signal Trends: Consistent low-risk signals with minimal threat indicators across recent observations
---
## Subnet Neighborhood Analysis (54.39.0.0/24)
- Total Siblings: 256
- Active Siblings: 230
- Threat Siblings: 111
- Abuse Density: 0.4336 (Mixed Classification)
- Inherited Risk: 17/100
- Neighbor Risk Distribution:
- High Risk: 0 IPs
- Medium Risk: 66 IPs
- Low Risk: 34 IPs
---
## Relationship Graph
- Total Relationships: 62
- Primary Association: OVH-CUST-281059683 (Same Network)
- Network Affiliation: Multiple same-network relationships indicating consistent OVH infrastructure assignment
---
## Control Plane Data
- Origin ASN: 16276
- BGP Prefix: 54.39.0.0/16
- Route Stability: Not stable
- MOAS Status: No
- RPKI State: Not available
- IRR Consistency: Not available
- DNSSEC Valid: Yes
- CAA Records: Yes
- DNSBL Listed: 1 of 8 lists
---
## Recommended Actions
No immediate security actions required. The IP demonstrates legitimate cloud hosting characteristics consistent with Ahrefs SEO infrastructure. No firewall rules or blocking recommendations are warranted at this time.
---
## Intelligence Assessment
IP 54.39.0.171 represents a low-risk endpoint within OVH's cloud hosting infrastructure. The absence of open ports, zero blacklist entries, and lack of threat indicators support classification as benign infrastructure. The subnet exhibits moderate mixed activity with 111 threat-sibling IPs, but the target IP itself maintains minimal risk posture. SOC analysts may monitor the subnet's overall abuse density trends but should not treat this specific IP as malicious based on current intelligence.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059683 |
| CIDR Block | 54.39.0.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca004-san171.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca004-san171.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 17% | 2 | 3 |
| ownership | 12% | 2 | 2 |
| reputation | 27% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 21% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-11 22:45:43 UTC |
| Last Seen | 2026-06-27 20:41:56 UTC |
| Profile Built | 2026-06-28 20:48:06 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 31 |
Full dossier details are available via our API.