# IP Intelligence Briefing: 54.39.210.100
Classification: MODERATE RISK
Date of Analysis: Current
Analyst: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
IP 54.39.210.100 is a cloud infrastructure endpoint hosted on OVH infrastructure in Quebec, Canada, associated with the ahrefs.net domain. The IP exhibits moderate risk characteristics with significant neighborhood abuse density and historical threat observations. While the IP itself shows no active threat indicators, it resides within a high-abuse subnet requiring monitoring.
---
## INFRASTRUCTURE PROFILE
Ownership & Registration
- Organization: Dmytro, Ahrefs Pte Ltd
- Netname: OVH-CUST-281059686
- ASN: 16276 (OVH SAS)
- CIDR Block: 54.39.210.0/24
- RIR Registry: ARIN
Geolocation
- Country: Canada (CA)
- Region: Quebec (QC)
- City: Beauharnois
- Coordinates: 45.3161°N, -73.8736°W
- Geolocation Confidence: PLAUSIBLE VIOLATION DETECTED
- RTT Anomaly: Measured 31ms RTT inconsistent with 5,629km distance (minimum expected 112.6ms)
Network Role
- Infrastructure Type: Cloud Compute
- Provider: OVH
- Classification: Hosting / Cloud Infrastructure
- Service Status: Firewalled / No Services Detected
- DNS PTR: proxy-ca007-san100.ahrefs.net
---
## RISK ASSESSMENT
Overall Risk Score: 40/100
| Component | Score | Assessment |
|---|---|---|
| Reputation | Moderate | - |
| Provider | 0 | Neutral |
| Authority | 0 | Neutral |
| Stability | 0 | Neutral |
| Inherited Risk | 32 | Elevated |
Threat Indicators
- Blacklist Count: 0
- DNSBL Listings: 1/8 lists
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
---
## NEIGHBORHOOD ANALYSIS
Subnet: 54.39.210.100/24
- Total Siblings: 256 IPs
- Active Siblings: 206 IPs
- Threat Siblings: 205 IPs
- Abuse Density: 80.08% (HIGH ABUSE CLASSIFICATION)
- Inherited Risk: 32/100
Risk Distribution in /24:
- High Risk: 0
- Medium Risk: 100
- Low Risk: 0
Finding: This subnet demonstrates pervasive medium-risk activity across 100+ neighbor IPs, all showing uniform risk scoring patterns. The high threat sibling count (205/256) indicates coordinated or shared infrastructure usage with elevated abuse potential.
---
## OBSERVATION HISTORY
Total Observations: 24 signals
Recent Activity Timeline:
- 2026-06-28 23:02: Threat indicators detected (AlienVault OTX)
- 2026-06-20 20:57: Geolocation signals with low confidence
- 2026-06-20 20:56: Abuse density classification (high_abuse)
- 2026-06-20 20:56: Port scan activity recorded
Temporal Indicators
- Threat Persistence: 0 days
- Ownership Changes: 0
- Is Persistently Malicious: No
- Threat Observation Count: 1
---
## RELATIONSHIP GRAPH
Total Relationships: 56 entities
Primary Associations:
- Network: OVH-CUST-281059686 (multiple relationships)
- Infrastructure Type: Same Network clusters
Analysis: The IP maintains extensive relationships within the OVH hosting infrastructure, indicating it is part of a larger cloud environment. No certificate-based or organizational relationships detected beyond network-level associations.
---
## SECURITY ACTIONS & RECOMMENDATIONS
Recommended Actions:
1. Monitor: Implement traffic monitoring for this IP due to moderate risk score and high-abuse neighborhood context
2. Geo-Validation: Investigate geolocation inconsistency (31ms RTT vs. 5,629km distance) - may indicate proxy usage or spoofing
3. DNSBL Review: Examine 1 DNSBL listing out of 8 total lists for context
4. Subnet Awareness: Apply subnet-level controls given 80% abuse density in /24
Firewall Considerations:
- No open ports detected - firewall rules may be unnecessary for this specific IP
- Monitor for service emergence
- Consider blocking at perimeter if traffic patterns align with threat indicators
---
## INTELLIGENCE CONCLUSIONS
IP 54.39.210.100 represents a MODERATE RISK cloud infrastructure endpoint within a HIGH ABUSE DENSITY subnet. While the IP itself shows no active malicious indicators and is associated with legitimate hosting infrastructure (ahrefs.net), the neighborhood context suggests elevated threat potential.
Key Concerns:
- Geolocation data integrity compromised (RTT anomaly)
- 80% abuse density in /24 subnet
- 205 threat siblings in same network
- Recent threat indicator detection
Recommended SOC Actions:
- Monitor for service emergence and traffic pattern changes
- Investigate geolocation anomaly
- Apply subnet-level observability controls
- Correlate with other ahrefs.net infrastructure
Priority: LOW-MEDIUM (Monitor rather than block)
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059686 |
| CIDR Block | 54.39.210.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca007-san100.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca007-san100.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 41% | 2 | 4 |
| routing | 20% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 30% | 3 | 3 |
| reputation | 32% | 1 | 3 |
| geolocation | 34% | 2 | 3 |
| Overall | 29% | 12 | 18 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-23 18:30:55 UTC |
| Last Seen | 2026-06-28 23:02:44 UTC |
| Profile Built | 2026-06-29 05:05:16 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 28 |
Full dossier details are available via our API.