IP Intelligence Briefing: 54.39.203.48
Date: June 15, 2026
---
**1. Risk Profile**
- Risk Score: 50 (Moderate Risk)
- Provider: OVH (ASN 16276)
- Ownership: Dmytro, Ahrefs Pte Ltd (Netname: OVH-CUST-281059687)
- Geolocation: Canada (QC, Beauharnois)
- Threat Indicators: No known malicious activity, no blacklists, no spam, no Tor exit nodes.
---
**2. Network Behavior**
- Hosting Role: Firewalled / No Services (likely a hosting or infrastructure IP).
- Subnet: 54.39.203.0/24
- Subnet Abuse Density: 45.78% (mixed classification, 18 inherited risk points).
- Neighbors: 249 IPs in subnet (122 active, 114 flagged as threats).
---
**3. Observational History**
- Recent Activity:
- Minimal risk score (0.2174 operator score) observed on June 15, 2026.
- Subnet abuse density increased to 0.5742 (high abuse classification) on June 15.
- No persistent malicious activity or threat persistence detected.
---
**4. Relationships**
- DNS Associations: Linked to `proxy-ca008-san48.ahrefs.net` (Ahrefs domain).
- Network Relationships: Same subnet (OVH-CUST-281059687).
- No Direct Threat Links: No known campaigns, malware, or malicious DNS records.
---
**5. Recommendations**
- Monitoring: Track subnet abuse density and neighbor risk scores for anomalies.
- Network Segmentation: Consider isolating this subnet if handling sensitive workloads.
- DNS Verification: Validate DNSSEC and CAA records for `ahrefs.net` to ensure no spoofing.
---
Conclusion:
The IP is associated with a hosting provider (OVH) and appears to be part of a mixed-use subnet with moderate abuse. No immediate threats detected, but continuous monitoring is advised due to the subnetβs risk profile. No urgent action required unless new threats emerge.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059687 |
| CIDR Block | 54.39.203.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca008-san48.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca008-san48.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 22% | 1 | 2 |
| geolocation | 25% | 2 | 2 |
| Overall | 20% | 10 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-21 02:52:26 UTC |
| Last Seen | 2026-06-28 13:05:57 UTC |
| Profile Built | 2026-06-29 07:11:16 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 22 |
Full dossier details are available via our API.