# Intelligence Briefing: 54.39.203.174/32
## Executive Summary
IP address 54.39.203.174 presents a low-risk profile with an overall risk score of 25. The endpoint is associated with Ahrefs infrastructure hosted on OVH cloud services in Quebec, Canada. No active threat indicators were identified. Recommended action: Monitor but no immediate blocking required.
## Profile Analysis
- Risk Score: 25 (Low Risk)
- Reputation: Low Risk
- Provider: OVH (ASN 16276)
- Organization: Dmytro, Ahrefs Pte Ltd
- Network Block: 54.39.203.0/24 (OVH-CUST-281059687)
- Geolocation: Beauharnois, Quebec, Canada (CA)
- Infrastructure Type: CloudCompute/Hosting
- DNS Resolution: proxy-ca008-san174.ahrefs.net (ahrefs.net)
- Service Status: Firewalled/No Open Ports Detected
## Threat Indicators
- Blacklist Status: Listed on 1 of 8 DNSBLs (Operator Score: 0.2174 - Minimal)
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Campaign Associations: None identified
- Known Threats: No active threat indicators in profile
## Neighborhood Assessment
The IP resides within subnet 54.39.203.0/24 with the following characteristics:
- Abuse Density: 0.4531
- Classification: Mixed
- Total Siblings: 256
- Active Siblings: 229
- Threat Siblings: 116
- Risk Distribution: 0 high-risk, 64 medium-risk, 36 low-risk endpoints
The subnet shows moderate abuse activity typical of OVH cloud infrastructure, but the specific endpoint maintains low risk metrics.
## Historical Observations
Signal history from 2026-06-25 confirms:
- Consistent cloud infrastructure classification (OVH)
- Stable DNS resolution to ahrefs.net domain
- No ownership or threat profile changes observed
- Threat persistence days: 0 (not persistently malicious)
## Recommended Actions
- Immediate Action: No blocking required
- Firewall Rules: None recommended based on current risk profile
- Monitoring Level: Standard observation
- Exception Handling: No exceptions needed
## Conclusion
IP 54.39.203.174 represents legitimate infrastructure for Ahrefs (legitimate SEO analytics platform) hosted on OVH cloud services. The low risk score, absence of active threat indicators, and association with a known legitimate service provider indicate this endpoint should be treated as benign. Standard monitoring practices apply.
Classification: LOW RISK - No Immediate Action Required
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059687 |
| CIDR Block | 54.39.203.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca008-san174.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca008-san174.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 23% | 2 | 2 |
| Overall | 20% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-08 23:18:43 UTC |
| Last Seen | 2026-06-27 14:42:27 UTC |
| Profile Built | 2026-06-28 08:47:09 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 26 |
Full dossier details are available via our API.