# IP Intelligence Briefing: 54.39.136.98/32
Date: June 2026
Classification: Moderate Risk
Analyst: IPDebrief Intelligence Team
---
## Executive Summary
IP 54.39.136.98 is a cloud infrastructure address operated by OVH (ASN 16276), hosted under customer network OVH-CUST-281059681. The IP resolves to ares.net domain infrastructure and maintains moderate risk posture with historical evidence of DNS blacklist listings and elevated subnet abuse density. No active threat indicators or campaign correlations detected.
---
## Network Profile
| Attribute | Value |
|---|---|
| **IP Address** | 54.39.136.98/32 |
| **Risk Score** | 40 (Moderate Risk) |
| **Organization** | Dmytro, Ahrefs Pte Ltd |
| **ASN** | 16276 (OVH) |
| **CIDR Block** | 54.39.136.0/24 |
| **Location** | Beaucharnois, QC, Canada |
| **Infrastructure Type** | Cloud Compute |
| **Network Role** | Hosting Provider |
---
## DNS Resolution
- Primary A Record: proxy-ca002-san98.ahrefs.net
- Domain: ahrefs.net
- Forward Confirmation: False
- PTR Record: proxy-ca002-san98.ahrefs.net
- Forward Resolution Count: 1
---
## Threat Indicators
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0 (current)
- DNSBL Listings: 1 of 8 total lists checked
- Known Campaigns: None detected
- Threat Feeds: No active matches
---
## Subnet Neighborhood Analysis (54.39.136.0/24)
| Metric | Value |
|---|---|
| **Abuse Density** | 0.549 (High Abuse Classification) |
| **Total Siblings** | 255 |
| **Active Siblings** | 144 |
| **Threat Siblings** | 140 |
| **Inherited Risk** | 21 |
| **Risk Distribution** | 99 Medium, 1 Low, 0 High |
Assessment: The /24 subnet exhibits elevated abuse activity with 140 of 144 active sibling IPs flagged as threats. This IP carries inherited risk from neighborhood context.
---
## Historical Signal Evolution
- Total Observations: 24
- Recent Activity: June 14-19, 2026
- Key Historical Signals:
- DNS blacklist listings (June 14, 2026): Listed on 8 total lists, 1 with high severity
- Subnet abuse density classification: High abuse (0.549)
- Geolocation signals from Canada
- Operator score: 0.2174 (Minimal)
---
## Control Plane & Routing
- Origin ASN: 16276
- BGP Prefix: 54.39.0.0/16
- Route Stability: False (changes detected in 30-day window)
- RPKI State: Not verified
- IRR Consistency: Not verified
- Route Changes (30d): 0
---
## Network Services
- Open Ports: None detected
- TLS Certificate: No certificate
- HTTP Banner: No response
- Service Status: Firewalled / No Services
---
## Recommended Actions
Immediate:
- Monitor inbound/outbound connections for anomalies
- Be aware of broader subnet abuse context (high abuse density)
- No immediate blocking required (moderate risk, no active threats)
Long-term:
- Correlate with other 54.39.136.0/24 addresses showing similar patterns
- Monitor for DNSBL listing additions
- Track for service emergence (currently firewalled)
---
## Intelligence Notes
This IP represents infrastructure associated with ares.net services. The moderate risk score reflects historical DNS blacklist activity and elevated neighborhood abuse density rather than active malicious indicators. The subnet's high abuse classification warrants awareness for traffic patterns but does not indicate this specific IP is currently compromised.
Status: Monitor - No Immediate Action Required
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059681 |
| CIDR Block | 54.39.136.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca002-san98.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca002-san98.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 23% | 2 | 2 |
| Overall | 20% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-08 23:18:42 UTC |
| Last Seen | 2026-06-27 14:41:52 UTC |
| Profile Built | 2026-06-28 08:47:09 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 28 |
Full dossier details are available via our API.