IP Intelligence Briefing: 54.39.203.122
Date: 2026-06-10
---
**1. IP Profile**
- Risk Score: 25 (Low Risk)
- Ownership:
- ASN: 16276 (OVH)
- Organization: Dmytro, Ahrefs Pte Ltd
- Network: 54.39.203.0/24 (OVH-CUST-281059687)
- Geolocation:
- Country: Canada (QC, Beauharnois)
- Traceroute Discrepancy: Claims location at 56.13°N, -106.35°W (likely Alaska/Canada border), but RTT analysis shows inconsistency with claimed distance (5629km vs. minimum possible RTT of 112.6ms).
- Network Role:
- Infrastructure: CloudCompute (OVH)
- Services: No open ports, no TLS certificates, no HTTP services.
- Threat Indicators:
- No malicious indicators, spam, or known attacker associations.
---
**2. Observation History**
- Recent Activity (2026-06-10):
- Geolocation: Confirmed in Canada (QC) with 3000km accuracy radius.
- Network Stability: BGP route stability score: 0.2174 (Minimal).
- DNS: Linked to `proxy-ca008-san122.ahrefs.net` (Ahrefs).
- Traceroute Anomaly:
- RTT Violation: Observed 31ms RTT vs. minimum possible 112.6ms for 5629km distance.
- Geo-Plausibility: Marked as false due to distance inconsistency.
---
**3. Relationships**
- Network Associations:
- Part of OVH subnet 54.39.203.0/24 (ASN 16276).
- DNS-linked to proxy-ca008-san122.ahrefs.net (Ahrefs).
- Subnet Analysis:
- Abuse Density: 0.4779 (moderate risk).
- Threat Siblings: 119 IPs in subnet flagged as threats.
---
**4. Neighborhood Risk**
- Subnet: 54.39.203.0/24
- Risk Distribution:
- High Risk: 0 IPs
- Medium Risk: 79 IPs
- Low Risk: 21 IPs
- Key Neighbors:
- IPs like `54.39.203.0`, `54.39.203.1`, and `54.39.203.3` show higher risk scores (40) and authority scores (50).
---
**5. Actionable Insights**
- SOC Recommendation:
- Monitor: The IPโs subnet (54.39.203.0/24) has a moderate abuse density; investigate potential lateral movement or compromised neighbors.
- Verify Geolocation: The RTT anomaly suggests spoofing or routing issues; validate geolocation data with additional probes.
- DNS Monitoring: Track DNS activity for `proxy-ca008-san122.ahrefs.net` for unusual traffic patterns.
- Firewall Rules (Example):
- iptables: `iptables -A INPUT -s 54.39.203.122 -j DROP` (if high-risk behavior is confirmed).
- Cloudflare WAF: Block IPs in the subnet with high-risk scores.
---
Conclusion: 54.39.203.122 is low-risk but resides in a subnet with moderate abuse. The geolocation inconsistency and subnet risk profile warrant closer monitoring for anomalies.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059687 |
| CIDR Block | 54.39.203.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca008-san122.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca008-san122.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 41% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 23% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 22% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-25 06:42:30 UTC |
| Last Seen | 2026-06-29 01:24:26 UTC |
| Profile Built | 2026-06-29 07:26:26 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.