IP Intelligence Briefing: 54.39.203.154
Date: 2026-06-12
---
**1. Core Profile**
- Risk Score: 25 (Low Risk)
- Ownership:
- ASN: 16276 (OVH)
- Organization: Dmytro, Ahrefs Pte Ltd
- Subnet: 54.39.203.0/24
- Geolocation:
- Country: Canada (QC, Beauharnois)
- Distance Discrepancy: 5628 km (claimed vs. actual)
- RTT Anomaly: 29ms (below expected 112ms for distance)
- Network Role:
- Cloud Compute (OVH-hosted)
- No active services or TLS certificates detected
---
**2. Threat & Behavior**
- Threat Indicators:
- No malware, spam, or campaign associations.
- No DNSBL listings or blacklisted activity.
- Behavioral Flags:
- Honeypot hits: 0
- Enumeration attempts: 0
- No suspicious TLS/HTTP banners or server fingerprints.
---
**3. Observation History**
- Key Event (June 12, 2026):
- Geolocation spoofing suspected: Claimed location (Beauharnois, Canada) does not align with actual distance (5628 km).
- RTT anomaly: 29ms (far below expected minimum for distance).
- Subnet Abuse Density: 0.498 (moderate risk).
---
**4. Network Relationships**
- Associated Hostnames:
- `proxy-ca008-san154.ahrefs.net` (Ahrefs infrastructure).
- Network Connections:
- Same ASN (OVH) and subnet (54.39.203.0/24).
- Subnet classification: "Mixed" (124 threatening siblings in 249 total).
---
**5. Neighborhood Analysis**
- Subnet Risk Distribution:
- 81 IPs: Medium risk (score 40β50).
- 19 IPs: Low risk.
- 0 IPs: High risk.
- Abuse Density: 0 (no confirmed malicious activity in subnet).
---
**6. Recommendations**
1. Monitor Subnet: The 54.39.203.0/24 subnet has a moderate abuse density. Continuously track new IPs for anomalies.
2. Verify Geolocation: Investigate the 5628 km distance discrepancy and RTT anomaly. This could indicate spoofing or a data center proxy.
3. Check Hostname Activity: Monitor `proxy-ca008-san154.ahrefs.net` for unexpected traffic or DNS changes.
4. Baseline Behavior: No active threats detected, but the IPβs association with Ahrefs (a cybersecurity company) warrants cautious monitoring.
Conclusion: This IP is part of a low-risk cloud hosting environment, but its geolocation discrepancy and subnetβs mixed risk profile suggest further investigation is warranted. No immediate action is required, but ongoing monitoring is advised.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059687 |
| CIDR Block | 54.39.203.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca008-san154.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca008-san154.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 19% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 13% | 1 | 2 |
| geolocation | 24% | 2 | 3 |
| Overall | 17% | 9 | 11 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-30 00:20:40 UTC |
| Last Seen | 2026-06-29 07:07:58 UTC |
| Profile Built | 2026-06-29 07:13:33 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.