# IP INTELLIGENCE BRIEFING: 54.39.136.241/32
## Executive Summary
IP 54.39.136.241 operates as a cloud compute hosting infrastructure endpoint within the OVH network (AS16276) in Canada. The IP presents a moderate risk profile (score: 50) with no direct threat indicators but exhibits geovalidation inconsistencies and is associated with the ahrefs.net domain.
## Network Profile
- IP Address: 54.39.136.241/32
- ASN: 16276 (OVH)
- Organization: Dmytro, Ahrefs Pte Ltd
- Network: OVH-CUST-281059681
- CIDR Block: 54.39.136.0/24
- Geolocation: Beauharnois, QC, Canada (CA)
- Infrastructure Type: Cloud Compute / Hosting
## Threat Assessment
Risk Score: 50 (Moderate Risk)
Key Findings:
- No active threat indicators detected
- No known campaigns or attacker associations
- No spam source classification
- Not a Tor exit node or VPN service
- No open ports detected (service purpose: Firewalled / No Services)
- Listed on 2 DNSBL entries across 8 total blacklist categories with maximum severity: HIGH
Abuse Context:
- Subnet 54.39.136.0/24 classified as HIGH_ABUSE
- Abuse density: 0.6797 (elevated)
- 174 of 256 total IPs in subnet flagged as threat siblings
- 182 active siblings observed
## Technical Indicators
DNS Resolution:
- PTR Hostname: proxy-ca002-san241.ahrefs.net
- Domain: ahrefs.net
- Forward resolution count: 1
Control Plane:
- BGP Prefix: 54.39.0.0/16
- Route stability: Unstable
- DNSSEC Valid: Yes
- Has CAA records: Yes
- RPKI State: Not available
## Observation History (17 signals)
Recent observations reveal:
- 2026-06-16: Provider identified as OVH hosting infrastructure
- 2026-06-16: Listed on multiple blacklist categories (max severity: HIGH)
- 2026-06-16: Domain ahrefs.net confirmed via DNS association
- 2026-06-16: Geographic validation failure detected
Geolocation Anomaly:
- Claimed location: Canada (QC)
- Inferred location: Canada (QC)
- Distance: 5628.6 km
- RTT Violation: 27.0ms measured vs. 112.6ms minimum possible
- Confidence: 0.35 (low)
- Validation status: GeoPlausible: FALSE
## Relationship Graph
- 12 total relationships identified
- 6 "Same Network" relationships to OVH-CUST-281059681
- 6 DNS Association relationships to proxy-ca002-san241.ahrefs.net
## Recommended Actions
Firewall Rules:
- `iptables -A INPUT -s 54.39.136.241 -j DROP`
- `nft add rule inet filter input ip saddr 54.39.136.241 drop`
- `nginx: deny 54.39.136.241;`
WAF Configuration:
- Cloudflare WAF: Block IP (Risk Score: 50)
- AWS WAF: Add to blocklist (54.39.136.241/32)
Contextual Note:
The subnet abuse density is elevated (0.6797), with 174 threat siblings identified. The IP's geolocation validation failure (RTT discrepancy) suggests potential spoofing or misattribution. While the IP currently lacks direct threat indicators, the hosting classification and blacklist associations warrant monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059681 |
| CIDR Block | 54.39.136.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca002-san241.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca002-san241.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 17% | 1 | 2 |
| geolocation | 32% | 2 | 3 |
| Overall | 20% | 9 | 11 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-08 16:05:48 UTC |
| Last Seen | 2026-06-24 07:30:11 UTC |
| Profile Built | 2026-06-21 15:21:50 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 22 |
Full dossier details are available via our API.