# Threat Intelligence Briefing: 54.39.136.149
Classification: Moderate Risk (Score: 40)
Analysis Date: Current
## Executive Summary
IP address 54.39.136.149 is assigned to OVH cloud infrastructure (ASN 16276) with DNS resolution to ahrefs.net. The IP resides in a subnet with high abuse density (0.7031), though the specific address shows no direct threat indicators. Recommended action: Monitor with awareness of subnet risk profile.
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 40 (Moderate) |
| **Provider** | OVH (CloudCompute/Hosting) |
| **Organization** | Dmytro, Ahrefs Pte Ltd |
| **CIDR Block** | 54.39.136.0/24 |
| **Geolocation** | Canada (QC, Beaucharnois) |
| **Status** | Firewalled / No Services |
| **DNS** | proxy-ca002-san149.ahrefs.net |
## Threat Assessment
Direct Threat Indicators: None detected
- No known attacker designation
- No spam source classification
- No known campaign affiliations
- Zero blacklisted on major threat feeds
Control Plane Data:
- DNSBL Listed: 1 of 8 total lists
- Operator Score: 0.2174 (Minimal)
- DNSSEC Valid: Yes
- Route Stability: Flagged as unstable
## Neighborhood Context
Subnet: 54.39.136.0/24
- Abuse Density: 0.7031 (High Abuse Classification)
- Threat Siblings: 180 of 256 total IPs
- Active Siblings: 185
- Inherited Risk: 28
Risk Distribution: 0 High, 16 Medium, 84 Low
## Temporal Analysis
17 observations recorded with latest data from June 2026. Signal persistence shows stable infrastructure assignment with no ownership changes. Geo validation flagged RTT anomaly (28ms observed vs 112.6ms minimum for reported distance), suggesting geolocation data may be unreliable.
## Relationship Graph
25 relationships identified:
- 25 Same Network entries (OVH-CUST-281059681)
- Multiple DNS Association entries (proxy-ca002-san149.ahrefs.net)
## SOC Recommendations
1. No Immediate Blocking Required โ IP shows no direct threat indicators
2. Monitor Subnet Activity โ High abuse density warrants awareness of potential related threats
3. Verify Legitimacy โ Confirm expected Ahrefs service usage patterns
4. Review DNSBL Listings โ Investigate which 1 of 8 lists contains this IP
5. Geolocation Validation โ Cross-reference with internal telemetry due to RTT anomaly
## Actionable Firewall Rules
No specific blocking rules recommended at this time. Maintain standard logging and monitoring for the 54.39.0.0/16 prefix given neighborhood risk profile.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059681 |
| CIDR Block | 54.39.136.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca002-san149.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca002-san149.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 32% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 21% | 9 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-25 06:42:29 UTC |
| Last Seen | 2026-06-29 01:24:15 UTC |
| Profile Built | 2026-06-29 07:26:26 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 20 |
Full dossier details are available via our API.