IP INTELLIGENCE BRIEFING: 54.39.210.193/32
EXECUTIVE SUMMARY
IP address 54.39.210.193 is an OVH cloud infrastructure endpoint located in Canada (QC, Beauharnois). The IP carries a moderate risk score (40/100) and is part of a high-abuse density subnet (0.7969). No active services were detected; the endpoint is firewalled with no open ports. The DNS hostname (proxy-ca007-san193.ahrefs.net) indicates association with Ahrefs infrastructure.
OWNERSHIP & INFRASTRUCTURE
- Organization: Dmytro, Ahrefs Pte Ltd
- ASN: 16276 (OVH)
- Network: OVH-CUST-281059686
- CIDR Block: 54.39.210.0/24
- Infrastructure Type: CloudCompute / Hosting
- Geolocation: Canada (QC, Beauharnois)
THREAT POSTURE
- Risk Score: 40 (Moderate Risk)
- Threat Indicators: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 lists
NETWORK CONTEXT
The /24 subnet (54.39.210.0/24) demonstrates elevated abuse characteristics:
- Abuse Density: 0.7969 (High Abuse)
- Classification: high_abuse
- Total Siblings: 256
- Active Siblings: 178
- Threat Siblings: 204
- Inherited Risk: 31
DNS & SERVICES
- PTR Hostname: proxy-ca007-san193.ahrefs.net
- Forward Resolution: proxy-ca007-san193.ahrefs.net
- Open Ports: None (firewalled/no services)
- TLS Certificate: None detected
- Email Authentication: SPF/DMARC not configured
OBSERVATION HISTORY
Analysis of 21 observations reveals consistent infrastructure classification:
- Cloud-based hosting (OVH)
- Persistent classification as cloud infrastructure
- No significant behavioral changes detected
- Latest observation: 2026-06-28
CONTROL PLANE
- Origin ASN: 16276
- BGP Prefix: 54.39.0.0/16
- Route Stability: Unstable
- DNSSEC: Valid
- Operator Score: 0.2174 (Minimal)
RECOMMENDED ACTIONS
Given the moderate risk profile and high-abuse subnet environment:
- Monitor for anomalous traffic patterns
- Review firewall rules for subnet-level filtering
- Consider blocking at edge if traffic is unexpected
- No immediate blocking recommended for known Ahrefs services
FIREWALL RULES
- iptables: `iptables -A INPUT -s 54.39.210.193 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 54.39.210.193 drop`
- Cloudflare WAF: Block with expression `ip.src eq 54.39.210.193`
- AWS WAF: Add `54.39.210.193/32` to blocked addresses
ANALYST NOTES
This endpoint represents legitimate cloud infrastructure in a high-density abuse subnet. The Ahrefs hostname association suggests potential legitimate use, but the subnet's abuse density warrants monitoring. Correlate with internal traffic logs to determine necessity of blocking.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059686 |
| CIDR Block | 54.39.210.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca007-san193.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca007-san193.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 14:58:06 UTC |
| Last Seen | 2026-06-28 14:45:12 UTC |
| Profile Built | 2026-06-29 08:50:35 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.