IP Intelligence Briefing: 54.39.210.124
Date: 2026-06-14
---
**1. Core Profile**
- Risk Rating: Moderate Risk (Score: 50)
- Ownership:
- ISP: OVH (ASN: 16276)
- Organization: Ahrefs Pte Ltd (Netname: OVH-CUST-281059686)
- Location: Canada (QC, Beauharnois)
- Threat Indicators:
- No malicious indicators, blacklists, or campaigns detected.
- Geolocation Discrepancy: RTT (24ms) inconsistent with claimed distance (5,629km), suggesting spoofed location or misconfigured routing.
---
**2. Network Context**
- Subnet: 54.39.210.0/24
- Subnet Abuse Density: 51.38% (High Abuse Classification)
- Neighbors:
- 253 IPs in subnet, 140 active, 130 flagged as malicious.
- Risk Distribution: 94 medium-risk IPs, 5 low-risk IPs.
- Network Role: Hosting provider (OVH) infrastructure; no CDN, VPN, or residential traffic detected.
---
**3. Historical Observations**
- Recent Activity (Last 30 Days):
- No persistent threat signals or ownership changes.
- Geolocation anomalies persist, indicating potential spoofing.
- BGP routing stability: 0 route changes, but "route stable" flag unset.
---
**4. Relationships & Dependencies**
- Linked Entities:
- Subnet: 54.39.210.0/24 (OVH-CUST-281059686)
- Hostname: `proxy-ca007-san124.ahrefs.net` (Ahrefs domain).
- DNS:
- PTR record resolves to Ahrefs-hosted domain.
- No email authentication (SPF/DKIM) detected.
---
**5. Security Recommendations**
- Monitor Subnet: High abuse density in 54.39.210.0/24 warrants increased scrutiny of neighboring IPs.
- Verify Geolocation: Investigate spoofed location; consider network misconfigurations or adversary tactics.
- Secure Hosting Infrastructure: Ensure Ahrefs-hosted servers are hardened against DDoS and unauthorized access.
- BGP Security: Validate BGP route stability and consider RPki implementation for OVH ASN 16276.
---
Conclusion: The IP is part of a high-abuse subnet operated by OVH for Ahrefs hosting. While no direct malicious activity is detected, the geolocation discrepancy and subnet risk profile suggest potential for collateral compromise. SOC teams should prioritize monitoring adjacent IPs and validating network configurations.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059686 |
| CIDR Block | 54.39.210.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca007-san124.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca007-san124.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 22% | 1 | 2 |
| geolocation | 30% | 2 | 3 |
| Overall | 22% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:29 UTC |
| Last Seen | 2026-06-27 08:29:52 UTC |
| Profile Built | 2026-06-28 02:36:16 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 25 |
Full dossier details are available via our API.