## INTELLIGENCE BRIEFING: 54.39.136.247/32
Classification: Moderate Risk | Report Date: Current | Confidence: High
Executive Summary
IP address 54.39.136.247 is a cloud-hosted infrastructure address assigned to Ahrefs Pte Ltd under OVH hosting services (ASN 16276). The address resolved to proxy-ca002-san247.ahrefs.net and is geolocated to Beauharnois, QC, Canada. While the IP itself shows moderate risk (score: 40), the /24 subnet demonstrates elevated abuse density (0.7031), with 180 of 256 sibling IPs flagged as threats.
Technical Profile
Ownership and Infrastructure:
- Organization: Dmytro, Ahrefs Pte Ltd
- ASN: 16276 (OVH)
- Network Block: 54.39.136.0/24
- Infrastructure Type: CloudCompute/Hosting
- Connection Status: Firewalled, no open services detected
Geolocation Validation:
- Reported Location: Beauharnois, QC, Canada
- Validation Status: GeoPlausible flag failed
- RTT Discrepancy: Measured 27ms against minimum possible 112.6ms for 5,628km distance
- This suggests potential geolocation spoofing or data inconsistency
DNS and Network Indicators
DNS Resolution:
- PTR Hostname: proxy-ca002-san247.ahrefs.net
- Forward Resolution: 1 record confirmed
- Email Authentication: No SPF, DMARC, or TXT records present
Threat Indicators:
- DNSBL Status: Listed on 1 of 8 total blacklists
- Tor Exit/VPN/Proxy: Negative
- Known Attacker/Spam Source: Negative
- Campaign Association: None detected
Neighborhood Analysis
Subnet Context (54.39.136.0/24):
- Abuse Density: 0.7031 (high_abuse classification)
- Active Siblings: 184 of 256 total IPs
- Threat Siblings: 180 flagged as malicious
- Risk Distribution: 0 high, 38 medium, 62 low risk
The elevated neighborhood abuse density indicates this subnet hosts mixed legitimate and compromised infrastructure, requiring contextual analysis rather than blanket blocking.
Observation History
Temporal Signals:
- Total Observations: 27 events recorded
- Recent Activity: Infrastructure and DNS signals observed June 2026
- Persistence: Not classified as persistently malicious
- Threat Persistence Days: 0
The address has demonstrated stable ownership with no significant threat pattern evolution over the observation period.
Intelligence Assessment
Primary Findings:
1. Legitimate cloud hosting infrastructure for Ahrefs-related services
2. Geo-location data validation failed; RTT anomalies present
3. Subnet exhibits high abuse density (70.3%)
4. No active malicious activity directly associated with this IP
Contextual Considerations:
- The address operates within an OVH-hosted cloud environment
- DNS infrastructure indicates web proxy functionality
- Neighboring IPs show significant abuse correlation (180 threat siblings)
- Blacklist presence (1 of 8 lists) warrants monitoring
Recommendation:
Allow traffic while monitoring for anomalous behavior patterns. The moderate risk score (40) combined with high-density neighborhood suggests contextual filtering may be more appropriate than outright blocking. Implement rate limiting and behavioral monitoring to distinguish legitimate Ahrefs traffic from potential abuse originating from the same subnet.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059681 |
| CIDR Block | 54.39.136.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca002-san247.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca002-san247.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 37% | 3 | 5 |
| reputation | 28% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 30% | 12 | 20 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 21:01:07 UTC |
| Last Seen | 2026-06-28 16:37:01 UTC |
| Profile Built | 2026-06-29 10:41:56 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 31 |
Full dossier details are available via our API.