# IP Intelligence Briefing: 54.39.210.196
## Executive Summary
The target IP 54.39.210.196 presents a Moderate Risk profile (Risk Score: 40) operating within OVH's cloud infrastructure in Canada. The IP is associated with the Ahrefs Pte Ltd organization and is hosted on the 54.39.210.0/24 subnet, which exhibits high abuse density characteristics.
## Infrastructure Profile
- Provider: OVH (ASN 16276)
- Organization: Dmytro, Ahrefs Pte Ltd
- Netblock: OVH-CUST-281059686 (54.39.210.0/24)
- Geolocation: Canada, Quebec, Beauharnois (coordinates: 45.3161°N, -73.8736°W)
- Infrastructure Type: CloudCompute, Hosting environment
- Network Classification: Cloud-hosted, firewall with no active services
## DNS & Service Analysis
- PTR Hostname: proxy-ca007-san196.ahrefs.net
- Forward Resolution: proxy-ca007-san196.ahrefs.net
- Domain: ahrefs.net
- Services: No open ports detected
- TLS Certificate: None
- HTTP: No services responding
## Threat Indicators
- Known Campaigns: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Status: Listed on 1 of 8 DNS blocklists
- Abuse Confidence Score: Not available
## Subnet Context (54.39.210.0/24)
The /24 subnet demonstrates elevated risk characteristics:
- Abuse Density: 0.707 (High Abuse classification)
- Total Subnet Siblings: 256
- Active Siblings: 172
- Threat Siblings: 181
- Inherited Risk Score: 28
- Neighbor Risk Distribution: 100 medium-risk IPs, 0 high-risk IPs sampled
## Observation History
Analysis of 21 signal observations reveals:
- Most Recent: 2026-06-20
- Threat Persistence: 0 days (not persistently malicious)
- Ownership Changes: 0
- Key Finding: Geovalidation discrepancies detectedβRTT measurements indicate claimed distance of 5,628 km, but observed RTT (25-31ms) suggests the IP may not be located at the claimed coordinates.
## Risk Assessment
This IP presents moderate risk primarily due to its subnet-level abuse density. While the IP itself shows no direct threat indicators (no blacklist hits, not a Tor exit, not a known attacker), the hosting of 181 threat-sibling IPs within the same /24 suggests potential compromise of adjacent infrastructure or shared hosting abuse.
## Recommended Actions
1. Monitor: Track for changes in DNS resolution patterns
2. Blocklist Review: Evaluate 1 DNS blacklist listing for relevance
3. Subnet Context: Correlate traffic with other high-risk IPs in the 54.39.210.0/24 range
4. Geolocation Verification: Geovalidation discrepancies warrant additional validation if this IP appears in threat intelligence feeds
---
*Report generated: IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059686 |
| CIDR Block | 54.39.210.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca007-san196.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca007-san196.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-21 14:58:06 UTC |
| Last Seen | 2026-06-28 14:44:50 UTC |
| Profile Built | 2026-06-29 08:50:35 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.