# IP Intelligence Briefing: 54.39.203.58
Classification: Moderate Risk | Provider: OVH | Date: 2026-06-20
## Executive Summary
IP 54.39.203.58 is an OVH-hosted cloud infrastructure address associated with Ahrefs Pte Ltd organization. While the IP shows no direct threat indicators, it resides within a high-abuse subnet (54.39.203.0/24) with elevated neighborhood risk. The IP demonstrates cloud compute infrastructure characteristics with firewalled services and should be monitored but does not require immediate blocking without additional contextual signals.
## Ownership and Network Context
- Organization: Dmytro, Ahrefs Pte Ltd
- ASN: 16276 (OVH)
- CIDR Block: 54.39.203.0/24
- Network Type: CloudCompute / Hosting Infrastructure
- Geolocation: Quebec, Canada (Beauharnois region)
- Reverse DNS: proxy-ca008-san58.ahrefs.net
## Risk Assessment
| Metric | Value | Assessment |
|---|---|---|
| Overall Risk Score | 40 | Moderate Risk |
| Provider Score | 0 | Neutral |
| Authority Score | 0 | Neutral |
| Operator Score | 0.2174 | Minimal |
| Abuse Confidence | N/A | No direct abuse signal |
| Blacklist Count | 0 | Clean |
| DNSBL Listings | 1 of 8 | Minor listing present |
## Neighborhood Analysis (54.39.203.0/24)
The IP operates within a subnet exhibiting significant abuse patterns:
- Abuse Density: 0.6719 (High)
- Subnet Classification: high_abuse
- Active Siblings: 225 of 256 addresses
- Threat Siblings: 172 (67% of active addresses)
- Risk Distribution: 41 medium risk, 59 low risk, 0 high risk
This environment suggests the subnet is actively utilized for hosting services, with a notable portion showing malicious activity patterns.
## Technical Observations
- Services: No open ports detected
- Infrastructure: Cloud-hosted with firewall protections active
- DNSSEC: Valid
- RTT Validation: Discrepancy notedβ24ms measured RTT inconsistent with 5,629km reported distance (minimum expected: 112.6ms). This suggests potential geolocation data inaccuracies.
- Campaign Activity: None detected; 0 correlated IPs in known campaigns
- Persistence: Single threat observation; not classified as persistently malicious
## Historical Trend
Analysis of 21 signal observations reveals consistent infrastructure classification with no escalation in threat posture. The IP has not demonstrated increasing risk characteristics over the observation period.
## Recommended Security Actions
Based on current risk profile (score 40), the following controls are recommended:
Immediate Mitigation:
```bash
# iptables
iptables -A INPUT -s 54.39.203.58 -j DROP
# nftables
nft add rule inet filter input ip saddr 54.39.203.58 drop
# Cloudflare WAF
Filter: ip.src eq 54.39.203.58
Action: block
```
Operational Guidance:
- Monitor for behavioral anomalies if allowing traffic
- Consider subnet-level controls (54.39.203.0/24) given high abuse density
- Correlate with other observed malicious activity before implementing strict blocking
- Review DNSBL listing context to determine if blocking is warranted
## Intelligence Assessment
The IP represents moderate risk primarily due to neighborhood context rather than intrinsic malicious behavior. The absence of open services, clean blacklist status, and lack of persistent threat activity supports a monitoring approach over immediate blocking. Organizations with strict security postures may implement the recommended firewall rules, while others may opt to observe the IP's activity patterns before taking action.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059687 |
| CIDR Block | 54.39.203.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca008-san58.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca008-san58.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-22 03:10:33 UTC |
| Last Seen | 2026-06-28 18:02:22 UTC |
| Profile Built | 2026-06-29 06:05:37 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.