# IP Intelligence Briefing: 54.39.203.115/32
Classification: Moderate Risk | Reputation Score: 40/100
---
## Executive Summary
IP 54.39.203.115 is a cloud infrastructure address hosted by OVH (ASN 16276) with moderate risk characteristics. The IP resolves to a hostname associated with Ahrefs (proxy-ca008-san115.ahrefs.net) and is currently firewalled with no active services detected. While the IP itself shows minimal direct threat indicators, the /24 subnet exhibits high abuse density (0.6523), warranting contextual monitoring.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **ASN** | 16276 (OVH) |
| **Organization** | Dmytro, Ahrefs Pte Ltd |
| **CIDR Block** | 54.39.203.0/24 |
| **Country** | Canada (QC, Beauharnois) |
| **Infrastructure Type** | CloudCompute, Hosting |
| **DNS PTR** | proxy-ca008-san115.ahrefs.net |
| **Services** | None detected (Firewalled) |
---
## Risk Assessment
Current Risk Score: 40/100 (Moderate Risk)
Threat Indicators:
- No Tor exit node activity
- Not flagged as known attacker or spam source
- Zero blacklist entries
- DNSBL listed on 1 of 8 total lists
- No active open ports or TLS certificates
Network Context:
- Subnet Abuse Density: 0.6523 (High Abuse Classification)
- Inherited Risk: 26/100
- Subnet Activity: 217 of 256 total siblings active; 167 threat siblings
- Risk Distribution: 63 medium-risk neighbors, 37 low-risk neighbors
---
## Observations & History
Recent signal observations (June 2026) indicate consistent cloud/hosting infrastructure characteristics with minimal threat operator scoring. Historical abuse density signals were elevated on 2026-06-19. The IP maintains persistent cloud compute classification across multiple observation windows.
Notable Anomaly: Geolocation validation flagged RTT violation (27ms measured vs 112.6ms minimum expected for 5,629km distance), suggesting geolocation data may be inaccurate.
---
## Relationship Graph
IP maintains 56 relationships, predominantly classified as "Same Network" links to OVH-CUST-281059687. No external organizational or certificate-based relationships identified beyond the OVH network cluster.
---
## Recommended Actions
Firewall Rules Available:
- iptables: `iptables -A INPUT -s 54.39.203.115 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 54.39.203.115 drop`
- nginx: `deny 54.39.203.115;`
- Cloudflare/AWS WAF: Block rule configured with risk score 40
Analysis: No specific action recommendations generated due to lack of active threat indicators. However, subnet abuse density suggests defensive blocking may be appropriate for risk mitigation.
---
## Intel Summary
The IP operates within a high-density hosting environment (OVH Canada) with legitimate Ahrefs naming convention. Direct threat signals are absent, but the subnet's elevated abuse profile (167 of 256 siblings flagged as threats) indicates shared infrastructure risk. Monitor for lateral activity within the 54.39.203.0/24 block. Consider blocking if inbound traffic is observed, as firewall rules indicate the IP is not actively serving.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059687 |
| CIDR Block | 54.39.203.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca008-san115.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca008-san115.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-10 04:12:11 UTC |
| Last Seen | 2026-06-27 17:14:29 UTC |
| Profile Built | 2026-06-28 11:19:51 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.