IP Intelligence Briefing: 54.39.203.0
Date: 2026-06-06
---
**1. Core Profile**
- Risk Score: 25 (Low Risk)
- Provider: OVH (ASN 16276)
- Ownership: Registered to Ahrefs Pte Ltd (OVH-CUST-281059687)
- Geolocation: Canada (QC, Beauharnois), latitude/longitude unknown, 3km accuracy radius.
- Threat Status: No malicious indicators (no blacklists, Tor, or spam sources).
- Network Role: Hosting provider (cloud infrastructure, no residential/mobile traffic).
---
**2. Observation History**
- Abuse Density: 0.45 (moderate risk in subnet 54.39.203.0/24).
- Key Trends:
- Subnet classification: "mixed" (111/246 IPs flagged as threats).
- Recent risk spikes: 0.52 abuse density observed on 2026-06-06.
- No persistent malicious activity (threat persistence days: 0).
---
**3. Network Relationships**
- Linked Entities:
- OVH-CUST-281059687 (same network).
- DNS: PTR hostname `proxy-ca008-san0.ahrefs.net` (linked to Ahrefs).
- Certificates: No TLS certs detected.
- BGP: Route prefix `54.39.0.0/16`, stable routing with minimal changes.
---
**4. Subnet Neighborhood**
- Subnet: 54.39.203.0/24 (246 total IPs).
- Risk Distribution:
- 64 low-risk IPs (25.5% of subnet).
- 36 medium-risk IPs (14.5%).
- 111 high-risk IPs (45%).
- Active Siblings: 120 IPs (48.8% of subnet).
- Notable Neighbors:
- 54.39.203.1 (risk score: 40), 54.39.203.2โ5 (risk scores: 25).
---
**5. Security Actions**
- Recommended Rules: None required for this IP (low risk).
- Firewall/Network: Monitor subnet 54.39.203.0/24 for unusual traffic due to high-risk neighbors.
---
**6. Summary**
The IP 54.39.203.0 is associated with Ahrefs Pte Ltd (OVH) and appears to be part of a cloud hosting infrastructure. While the IP itself shows no malicious activity, its subnet has a moderate abuse density (45% high-risk neighbors). SOC teams should monitor the subnet for lateral movement or compromised hosts. No immediate action is required for this IP, but vigilance is advised due to the surrounding network risk.
Next Steps:
- Investigate high-risk neighbors in 54.39.203.0/24.
- Validate DNS records (`proxy-ca008-san0.ahrefs.net`) for potential abuse.
- Monitor for changes in subnet abuse density.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059687 |
| CIDR Block | 54.39.203.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca008-san0.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca008-san0.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 21% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-12 03:44:14 UTC |
| Last Seen | 2026-06-27 21:02:43 UTC |
| Profile Built | 2026-06-28 15:08:31 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.