# INTELLIGENCE BRIEFING: 54.39.136.74/32
## Executive Summary
IP address 54.39.136.74/32 is classified as Moderate Risk (Score: 40) and operates within OVH cloud infrastructure in Beauharnois, Quebec, Canada. The IP resolves to Ahrefs DNS infrastructure (proxy-ca002-san74.ahrefs.net) but is hosted in a subnet showing elevated abuse density. No active threat indicators were identified.
## Ownership & Infrastructure
- Organization: Dmytro, Ahrefs Pte Ltd
- ASN: 16276 (OVH)
- Network: 54.39.136.0/24
- Infrastructure Type: CloudCompute / Hosting
- Geolocation: Canada (QC, Beauharnois) โ 3000km accuracy radius
- DNS: proxy-ca002-san74.ahrefs.net (Ahrefs domain)
- Services: No open ports detected; firewalled/no services active
## Threat Assessment
- Risk Score: 40 (Moderate)
- Threat Indicators: None identified
- Not Tor exit node
- Not known attacker
- Not spam source
- Zero blacklist entries
- Campaign Correlation: No matches to known campaigns
- Threat Persistence: 0 days (not persistently malicious)
- DNSBL Status: Listed on 1 of 8 DNSBL feeds
## Neighborhood Analysis โ 54.39.136.0/24
- Abuse Density: 0.5586 (High abuse classification)
- Subnet Risk: Inherited risk score of 22
- Population: 256 total siblings, 152 active, 143 showing threat activity
- Risk Distribution: 99 medium, 1 low, 0 high risk neighbors
## Observation History
- Total Signals: 24 observations recorded
- Recent Activity: Cloud infrastructure classification (OVH) confirmed
- Geolocation Consistency: Quebec, Canada location consistently reported
- No Significant Changes: No escalation in threat posture detected over observation period
## Security Actions & Recommendations
| Platform | Recommended Action |
|---|---|
| iptables | `iptables -A INPUT -s 54.39.136.74 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 54.39.136.74 drop` |
| nginx | `deny 54.39.136.74;` |
| pfSense | Block 54.39.136.74/32 |
| Cloudflare WAF | Block โ IPDebrief risk score 40 |
| AWS WAF | Add 54.39.136.74/32 to block list |
## Intelligence Narrative for SOC
This IP is associated with Ahrefs (legitimate SEO analytics provider) but operates within a high-abuse-density OVH subnet. The moderate risk score (40) reflects the subnet context rather than direct threat indicators. The IP itself shows no active malicious behavior, but the neighborhood abuse density of 0.5586 suggests potential collateral risk from adjacent addresses. Monitor for any behavioral changes or service activation. Recommended action: Block at perimeter firewall pending additional intelligence correlation. No immediate IOC-based alerting required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059681 |
| CIDR Block | 54.39.136.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca002-san74.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca002-san74.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 30% | 3 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 28% | 12 | 18 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-17 15:13:42 UTC |
| Last Seen | 2026-06-28 05:33:31 UTC |
| Profile Built | 2026-06-28 23:38:21 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 30 |
Full dossier details are available via our API.