IP INTELLIGENCE BRIEFING: 54.39.203.195/32
Date: 2026-06-14
Classification: Moderate Risk
Status: Active
EXECUTIVE SUMMARY
IP 54.39.203.195 is a cloud-based infrastructure address associated with OVH (ASN 16276) hosting infrastructure under the organization "Dmytro, Ahrefs Pte Ltd." The IP demonstrates moderate risk characteristics with a risk score of 40. It resolves to the ahrefs.net domain and exhibits firewalled behavior with no publicly accessible services. The IP resides within a high-abuse density subnet (54.39.203.0/24) showing elevated neighborhood threat activity.
OWNERSHIP & INFRASTRUCTURE
- ASN: 16276 (OVH SAS)
- Organization: Dmytro, Ahrefs Pte Ltd
- CIDR Block: 54.39.203.0/24
- Infrastructure Type: Cloud Compute / Hosting
- Network Classification: Cloud Infrastructure (isCloud: true, isHosting: true)
- Geolocation: Canada, Quebec, Beauharnois (3000km accuracy radius)
- DNS Resolution: proxy-ca008-san195.ahrefs.net
THREAT PROFILE
- Risk Score: 40 (Moderate Risk)
- Abuse Confidence Score: Not quantified
- Blacklist Count: 0 direct blacklists
- DNSBL Listed: 1 of 8 total lists
- Known Attacker: False
- Tor Exit Node: False
- Spam Source: False
- Known Campaigns: None identified
- Threat Persistence: 0 days (no persistent malicious behavior observed)
NETWORK BEHAVIOR
- Open Ports: None detected (Firewalled / No Services)
- TLS/Certificate: No certificate information available
- HTTP Banner: None
- Service Purpose: Firewalled / No Services
- Infrastructure Stability: Stable ownership (0 ownership changes observed)
NEIGHBORHOOD CONTEXT
- Subnet: 54.39.203.0/24
- Abuse Density: 0.5664 (High Abuse Classification)
- Total Siblings: 256
- Active Siblings: 191
- Threat Siblings: 145
- Neighborhood Risk Distribution: 98 medium risk, 2 low risk, 0 high risk among sampled neighbors
OBSERVATION HISTORY
- Total Observations: 23 signals recorded
- Latest Activity: 2026-06-14T16:08:10 UTC
- Signal Consistency: Consistent identification as OVH cloud infrastructure across multiple observations
- DNS Resolution: Confirmed association with ahrefs.net domain
- Geolocation Signals: Multiple sources (CA/Quebec region consensus)
RELATIONSHIP GRAPH
- Total Relationships: 44
- Primary Association: Same Network (OVH-CUST-281059687)
- Related Entities: Network-level associations only (no external organization/hosting links)
RECOMMENDED ACTIONS
1. Monitor: No immediate blocking recommended. Continue monitoring for service emergence.
2. Baseline: Establish baseline for ahrefs.net domain activity from this subnet.
3. Context: Evaluate activity in context of neighborhood abuse density (145 threat siblings in /24).
4. Threat Intel: No specific threat indicators present; treat as legitimate cloud infrastructure with elevated neighborhood risk.
ASSESSMENT NOTES
The IP demonstrates characteristics of legitimate cloud infrastructure (ahrefs.net domain association) but operates within a high-abuse density subnet. The lack of open services and firewalled behavior suggests either legitimate backend infrastructure or potential covert operations. No direct malicious indicators detected, but neighborhood context warrants continued monitoring.
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059687 |
| CIDR Block | 54.39.203.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca008-san195.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca008-san195.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 12% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 23% | 2 | 2 |
| Overall | 19% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-10 16:14:41 UTC |
| Last Seen | 2026-06-27 18:08:11 UTC |
| Profile Built | 2026-06-28 12:12:35 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 25 |
Full dossier details are available via our API.