IP INTELLIGENCE BRIEFING: 54.39.0.238/32
Classification: Moderate Risk - High-Abuse Subnet Member
1. Ownership & Infrastructure
The IP address 54.39.0.238 is owned by OVH-CUST-281059683, associated with ASN 16276 (OVH) under organization "Dmytro, Ahrefs Pte Ltd." The subnet 54.39.0.0/24 is classified as hosting infrastructure with no open services detected. The IP shows cloud compute characteristics consistent with OVH hosting services.
2. Risk Assessment
- Risk Score: 40/100 (Moderate)
- Subnet Abuse Density: 0.6953 (High-Abuse Classification)
- Threat Siblings: 178 out of 256 total IPs in the /24 subnet flagged as threats (69.53%)
- Operator Score: 0.2174 (Minimal)
- DNSBL Listings: 1 of 8 total lists
3. Geolocation & Validation Anomalies
Geolocation data reports Canada (Quebec, Beauharnois), but RTT validation indicates significant inconsistency: observed RTT of 28ms versus minimum possible RTT of 112.6ms for the reported 5,629km distance from probe location. GeoPlausible flag is false, indicating data quality concerns.
4. Threat Indicators
- No known attack campaigns
- No Tor exit node activity
- Not classified as spam source
- No known attacker indicators
- Blacklist count: 0
5. Network Behavior & Services
- Service Purpose: Firewalled / No Services
- No open ports detected
- No TLS certificates
- PTR hostname: proxy-ca004-san238.ahrefs.net
- Domain association: ahrefs.net
6. Historical Observation
Sixty-one observations recorded since 2026-06-15. Recent observations confirm OVH cloud hosting classification. No persistent threat activity detected. Ownership has remained stable.
7. Recommended Security Actions
Based on subnet abuse density and threat sibling count, the following blocking rules are recommended:
Firewall Rules:
- iptables: `iptables -A INPUT -s 54.39.0.238 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 54.39.0.238 drop`
- nginx: `deny 54.39.0.238;`
- Cloudflare WAF: Block 54.39.0.238 (risk score 40)
- AWS WAF: Add 54.39.0.238/32 to IP set for blocking
Assessment: While the individual IP shows moderate risk, the high-abuse subnet environment (0.6953 abuse density) warrants defensive blocking. Consider broader subnet-level monitoring for 54.39.0.0/24 due to elevated threat sibling concentration.
Product: IPDebrief
Copyright: © 2026 Jason Alberino. All rights reserved.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059683 |
| CIDR Block | 54.39.0.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca004-san238.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca004-san238.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 40% | 3 | 5 |
| reputation | 31% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 29% | 12 | 20 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 21:01:06 UTC |
| Last Seen | 2026-06-28 16:33:36 UTC |
| Profile Built | 2026-06-29 04:38:31 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 29 |
Full dossier details are available via our API.