# IPDEBRIEF INTELLIGENCE BRIEFING
Target IP: 54.39.210.225/32
Classification: LOW RISK (35/100) | HIGH ABUSE SUBNET
Date: 2026-06-14
Provider: OVH (ASN 16276)
---
## EXECUTIVE SUMMARY
IP 54.39.210.225 is a cloud hosting infrastructure address assigned to OVH in Beauharnois, Quebec. While the individual IP carries a low risk score (35), it operates within a high-abuse density subnet (54.39.210.0/24) showing 0.6641 abuse density with 170 active threat siblings. The IP is associated with the domain ahrefs.net and is currently firewalled with no detectable open services.
---
## NETWORK PROFILE
Ownership & Classification:
- ASN: 16276 (OVH)
- Organization: Dmytro, Ahrefs Pte Ltd
- CIDR Block: 54.39.210.0/24
- Network Role: CloudCompute / Hosting Infrastructure
- Geolocation: Canada, Quebec, Beauharnois (3000km accuracy radius)
Infrastructure Status:
- Cloud Infrastructure: Yes
- CDN: No
- Proxy/VPN/Tor: No
- Residential: No
- Bogon: No
DNS Resolution:
- PTR Hostname: proxy-ca007-san225.ahrefs.net
- Forward Resolution: ahrefs.net
- Hosted Domain Count: 0
Network Control Plane:
- BGP Prefix: 54.39.0.0/16
- AS Path: 34549 16276
- Route Stability: Stable (0 route changes in 30 days)
- DNSSEC Valid: Yes
- IRR Consistency: Match
---
## THREAT INDICATORS
Current Threat Assessment:
- Risk Score: 35 (Low Risk)
- Abuse Confidence Score: Not Available
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0 (DNSBL: 1 listed / 8 total)
Signal History (27 Observations):
- 2026-06-14T14:22:46: Listed on 8 DNSBLs with 1 high-severity listing
- 2026-06-14T14:22:17: Operator Score 0.5652 (Moderate)
- 2026-06-14T14:23:49: Subnet classified as high_abuse (66.41% abuse density)
- 2026-06-14T14:27:12: Confirmed cloud hosting infrastructure
Threat Persistence:
- Threat Observation Count: 1
- Persistently Malicious: No
- Ownership Changes: 0
---
## SUBNET ANALYSIS
Neighborhood Profile (54.39.210.0/24):
- Abuse Density: 0.6641 (High)
- Classification: high_abuse
- Total Siblings: 256
- Active Siblings: 164
- Threat Siblings: 170
Neighbor Risk Distribution:
- High Risk: 0
- Medium Risk: 100 (sample of 100)
- Low Risk: 0
Inherited Risk Score: 26
Network Relationships:
- 57 relationships detected
- All relationships map to OVH customer network OVH-CUST-281059686
- No external organization or certificate relationships identified
---
## SERVICES & PORTS
Open Ports: None detected
HTTP Title: Not Available
TLS Certificate: Not Available
Server Banner: Not Available
Status: Firewalled / No Services
---
## RECOMMENDED ACTIONS
Risk Score: 35/100
Recommended Action: BLOCK (Firewall recommendation based on subnet abuse density and DNSBL listings)
Firewall Rules by Platform:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 54.39.210.225 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 54.39.210.225 drop` |
| nginx | `deny 54.39.210.225;` |
| pfSense | `54.39.210.225/32` (block rule) |
| Cloudflare WAF | Block IP 54.39.210.225 with description "IPDebrief risk score 35" |
| AWS WAF | Add 54.39.210.225/32 to IP blocklist with description "IPDebrief risk 35" |
---
## ANALYST NOTES
1. Subnet Context: While the individual IP shows low risk, the parent /24 subnet (54.39.210.0/24) exhibits high abuse density. The 170 threat siblings suggest this infrastructure block may host compromised endpoints or be used for malicious activities.
2. Infrastructure Type: The IP is confirmed as hosting infrastructure (OVH cloud). The PTR hostname suggests it may be part of a web proxy or caching infrastructure for ahrefs.net.
3. Monitoring Recommendation: Monitor for any service changes or port openings. The current firewall state prevents service enumeration.
4. Correlation Potential: Investigate any network activity from this IP alongside the 170 identified threat siblings in the same subnet for potential coordinated activity.
5. Geographic Consideration: The IP is geolocated to Canada (Quebec). Consider whether this aligns with expected legitimate traffic patterns for your organization.
---
Report Generated: 2026-06-14
Data Sources: IPDebrief Intelligence Platform
Classification: Internal Threat Intelligence
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059686 |
| CIDR Block | 54.39.210.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca007-san225.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca007-san225.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 24% | 3 | 4 |
| services | 12% | 2 | 2 |
| ownership | 30% | 3 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 23% | 2 | 2 |
| Overall | 25% | 13 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (65%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-09 17:41:41 UTC |
| Last Seen | 2026-06-27 16:29:09 UTC |
| Profile Built | 2026-06-28 10:35:33 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 30 |
Full dossier details are available via our API.