# INTELLIGENCE BRIEFING: 54.39.0.72/32
Classification: LOW RISK / LEGITIMATE INFRASTRUCTURE
## Executive Summary
IP 54.39.0.72 is a low-risk cloud compute endpoint hosted on OVH infrastructure in Canada. The address resolves to ahrefs.net with minimal threat indicators and stable ownership. No active malicious campaigns or attacker signatures detected.
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 25/100 (Low) |
| **ASN** | 16276 (OVH) |
| **Organization** | Dmytro, Ahrefs Pte Ltd |
| **Network Block** | 54.39.0.0/24 |
| **Geolocation** | Beauharnois, QC, CA |
| **Infrastructure Type** | CloudCompute / Hosting |
## Threat Assessment
- Blacklist Status: Clean (0 blacklist matches)
- Known Attacks: None detected
- Spam Source: Negative
- Tor Exit Node: Negative
- Active Threat Indicators: None
Control Plane Data:
- DNSBL Listed: 1 of 8 checks (dnsblListedCount)
- Operator Score: 0.2174 (Minimal risk)
- RPKI State: Not reported
- Route Stability: False (isRouteStable)
## Network Context
Subnet Analysis (54.39.0.0/24):
- Abuse Density: 0.4297 (moderate)
- Threat Siblings: 110 of 256 active IPs
- Risk Distribution: 0 high-risk, 67 medium-risk, 33 low-risk
- Classification: Mixed
Related Hosts (Sample):
- 54.39.0.0: Risk 25, Authority 50
- 54.39.0.1: Risk 40, Authority 50
- 54.39.0.2: Risk 25, Authority 50
## Network Services
- Open Ports: None detected (firewalled/no services)
- DNS Resolution: proxy-ca004-san72.ahrefs.net
- TLS Certificate: Not detected
- HTTP Services: Not detected
## Historical Observations
Total Observations: 23 signals recorded
Recent Trends:
- Ownership Changes: 0 (stable)
- Threat Persistence: 0 days
- Latest Signal (2026-06-27): Operator score 0.087 (minimal)
- Geolocation Consensus: True (single source, 3000km accuracy radius)
## Geographic Anomalies
RTT Violation Detected:
- Observed RTT: 28ms
- Minimum Possible RTT: 112.6ms (for 5629km distance)
- Note: This indicates data quality issues with geolocation database or potential routing anomalies.
## SOC Action Recommendations
1. Monitor, Block Not Recommended: Low-risk infrastructure with no active threat indicators
2. Contextual Monitoring: Given moderate subnet abuse density (0.4297), monitor for unusual outbound connections
3. DNS Verification: PTR record points to ahrefs.net infrastructure; validate against known ahrefs.net ranges if needed
4. Network Baseline: Compare against known OVH Canada ranges (ASN 16276)
## Conclusion
This IP represents legitimate cloud infrastructure with minimal threat posture. The single DNSBL listing and moderate neighborhood abuse density warrant standard monitoring practices but do not justify immediate blocking or escalation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059683 |
| CIDR Block | 54.39.0.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca004-san72.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca004-san72.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 27% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-09 11:34:10 UTC |
| Last Seen | 2026-06-27 15:48:11 UTC |
| Profile Built | 2026-06-28 15:53:32 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 27 |
Full dossier details are available via our API.