## IP Intelligence Briefing: 54.39.136.157
Target IP: 54.39.136.157/32
Risk Assessment: Low Risk (Score: 25/100)
Classification: Mixed-use CloudCompute infrastructure
Ownership & Infrastructure:
The IP address belongs to organization "Dmytro, Ahrefs Pte Ltd" under ASN 16276 (OVH). The address is hosted on OVH's cloud compute infrastructure within the 54.39.136.0/24 block. Geolocation data indicates Canada (QC, Beauharnois), though RTT validation shows anomalies suggesting geolocation data may be inaccurate. DNS PTR records resolve to proxy-ca002-san157.ahrefs.net under the ahrefs.net domain. No open ports or active services were detected; the host appears firewall-configured with no exposed services.
Threat Profile:
The IP maintains a low risk score of 25 with no active threat indicators. No known campaigns, attacker signatures, or spam source indicators were identified. Blacklist status shows 0 direct listings, though the IP appears on 8 DNSBLs with 1 listing at maximum severity. Operator classification is "Minimal" (0.2174 score). Historical observations confirm consistent cloud hosting classification with no evidence of persistent malicious activity.
Neighborhood Analysis:
The 54.39.136.0/24 subnet exhibits mixed classification with an abuse density of 0.4609. Of 256 total siblings, 189 are actively used and 118 are classified as threats. Risk distribution within the subnet shows 0 high-risk, 58 medium-risk, and 42 low-risk addresses. Neighbor IPs (e.g., 54.39.136.0, 54.39.136.1) display risk scores ranging from 25-40 with authority scores of 50.
Network Relationships:
The IP maintains 53 detected relationships, primarily "Same Network" associations with OVH-CUST-281059681. No certificate or hostname relationships beyond the PTR record were identified.
Security Recommendations:
No immediate firewall rules or blocking actions recommended based on current risk profile. The IP demonstrates low-risk characteristics typical of legitimate cloud hosting infrastructure. However, SOC teams should monitor the subnet's elevated abuse density (0.4609) and threat sibling count (118), as mixed-use hosting environments may attract opportunistic threats.
Historical Trend:
Observation history (20 signals) indicates stable characteristics with no significant risk escalation. The IP has not demonstrated persistent malicious behavior patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059681 |
| CIDR Block | 54.39.136.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca002-san157.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca002-san157.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 39% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 22% | 1 | 2 |
| geolocation | 31% | 2 | 3 |
| Overall | 23% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-10 10:13:58 UTC |
| Last Seen | 2026-06-27 17:37:27 UTC |
| Profile Built | 2026-06-28 11:41:37 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 26 |
Full dossier details are available via our API.