## IP INTELLIGENCE BRIEFING: 54.39.0.231/32
Classification: Moderate Risk (Score: 40) | Status: Active Monitoring Recommended
---
Network Identification
The IP address 54.39.0.231 belongs to ASN 16276 (OVH) and is allocated to organization "Dmytro, Ahrefs Pte Ltd" within CIDR block 54.39.0.0/24. The IP resolves to acloud computing infrastructure with hostname proxy-ca004-san231.ahrefs.net under the ahrefs.net domain. Current network classification indicates cloud hosting with no services actively listening.
Geolocation Assessment
Reported location: Beauharnois, Quebec, Canada. However, geolocation validation shows discrepanciesβRTT measurements indicate 27ms round-trip time versus a theoretical minimum of 112.6ms for the reported distance (5,629km), suggesting potential geolocation inaccuracy.
Threat Profile
No direct threat indicators are associated with this IP. Blacklist count remains zero. The IP is not flagged as a known attacker, spam source, or Tor exit node. However, the control plane data reveals one DNSBL listing among eight total lists.
Neighborhood Risk Analysis
The 54.39.0.0/24 subnet exhibits elevated abuse density (0.7148) with a high_abuse classification. Analysis of 256 sibling IPs reveals 227 active endpoints, with 183 classified as threat siblings and 42 as medium risk. The inherited risk score of 28 indicates contextual risk propagation from neighboring addresses.
Temporal Observations
Observation history contains 24 recorded signals. Recent activity confirms consistent association with OVH infrastructure (ASN 16276), cloud compute designation, and the ahrefs.net domain. No persistent malicious indicators detected over the observation period.
Recommended Actions
Immediate Recommendation: Block at network perimeter due to elevated neighborhood risk profile.
Firewall Rules:
- iptables: `iptables -A INPUT -s 54.39.0.231 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 54.39.0.231 drop`
- Cloudflare WAF: Block with expression `ip.src eq 54.39.0.231`
- AWS WAF: Add 54.39.0.231/32 to blocked addresses
Context: While the IP itself lacks direct malicious indicators, the high-abuse density neighborhood warrants defensive blocking. Correlate with additional telemetry before establishing long-term block policies.
---
Analyst Notes: The IP serves a legitimate application (Ahrefs.net) but operates within a high-risk hosting environment. Monitor for any behavioral changes or service emergence that could indicate abuse.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059683 |
| CIDR Block | 54.39.0.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca004-san231.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca004-san231.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 40% | 3 | 5 |
| reputation | 31% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 32% | 12 | 20 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-21 21:01:06 UTC |
| Last Seen | 2026-06-28 16:33:48 UTC |
| Profile Built | 2026-06-29 04:38:31 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 29 |
Full dossier details are available via our API.