# IP Intelligence Briefing: 54.39.136.189/32
## Executive Summary
IP 54.39.136.189 is a low-risk (Risk Score: 25) OVH Cloud Compute infrastructure address associated with Ahrefs Pty Ltd. While the IP itself shows minimal malicious activity, the /24 subnet demonstrates elevated abuse density (0.4609) with 118 threat siblings among 256 total addresses. No immediate blocking is recommended, but monitoring is advised given the neighborhood risk profile.
## Ownership & Classification
- Organization: Dmytro, Ahrefs Pte Ltd
- ASN: 16276 (OVH SAS)
- Network: OVH-CUST-281059681
- Infrastructure: Cloud Compute (OVH Cloud)
- Geolocation: Beauharnois, QC, Canada (geographic validation flagged implausible RTT of 27ms vs 112.6ms minimum for reported distance)
- Classification: Cloud hosting infrastructure, firewalled/no services detected
## Threat Profile
- Risk Score: 25 (Low Risk)
- Threat Indicators: None detected
- Known Attacker: No
- Spam Source: No
- Tor Exit: No
- DNSBL Listings: 1 of 8 lists (high severity classification)
- Open Ports: None detected
- TLS/HTTP Services: Not exposed
## Observation History Analysis
Recent signal observations reveal:
- DNS Resolution: Consistently resolves to proxy-ca002-san189.ahrefs.net (confidence 0.80-0.85)
- Subnet Context: /24 subnet classified as "mixed" with abuse density 0.4609
- Threat Persistence: No persistent malicious activity detected
- Blacklist Status: Currently listed on 1 blacklist with high severity rating
## Neighborhood Risk Assessment
The /24 subnet (54.39.136.0/24) shows:
- Total Siblings: 256
- Active Siblings: 189
- Threat Siblings: 118
- Risk Distribution: 54 medium-risk, 46 low-risk neighbors
- Abuse Density: 0.4609 (elevated for OVH cloud environment)
## Network Relationships
- 57 relationship connections detected
- All relationships map to same network identifier (OVH-CUST-281059681)
- No cross-network or organizational relationships identified
## Recommended Actions
No immediate firewall rules recommended based on current risk profile. The IP demonstrates legitimate cloud infrastructure characteristics with no active threat indicators. However, the following considerations apply:
1. Monitor DNSBL Status: IP is listed on 1 DNS blacklist with high severity
2. Subnet Awareness: Monitor /24 neighborhood for correlation with threat activity
3. Geographic Anomaly: Investigate geolocation discrepancy (RTT suggests ~5,600km distance vs claimed Canadian location)
## Intelligence Assessment
This IP represents legitimate cloud infrastructure associated with Ahrefs (SEO analytics company). The low individual risk score combined with cloud hosting characteristics suggests normal operational use. The neighborhood's elevated abuse density reflects OVH's multi-tenant cloud environment rather than coordinated threat activity. No immediate defensive action required; maintain baseline monitoring.
---
*Report generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059681 |
| CIDR Block | 54.39.136.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca002-san189.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca002-san189.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 22% | 9 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-11 08:59:12 UTC |
| Last Seen | 2026-06-27 19:24:17 UTC |
| Profile Built | 2026-06-28 13:30:16 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 24 |
Full dossier details are available via our API.