# IP Intelligence Briefing: 54.39.210.23
## Executive Summary
IP 54.39.210.23 is a moderate-risk cloud hosting address operated by OVH, with DNS records resolving to ahrefs.net infrastructure. The IP exhibits elevated neighborhood abuse density and is listed on DNS blacklists, warranting monitoring but no immediate blocking based on current threat indicators.
## Profile Overview
- Risk Score: 40 (Moderate Risk)
- Network: OVH-CUST-281059686 / 54.39.210.0/24
- Organization: Dmytro, Ahrefs Pte Ltd
- ASN: 16276 (OVH)
- Geolocation: Beauharnois, Canada (CA)
- Infrastructure Type: Cloud Compute / Hosting
- Status: Firewalled / No Active Services
## Threat Indicators
- DNSBL Listings: 1 of 8 total blacklist entries
- Known Campaigns: None identified
- Tor/Proxy/VPN: Not classified as Tor exit node, proxy, or VPN
- Abuse Confidence: Insufficient data for precise scoring
- Threat Persistence: No persistent malicious activity observed
## Network Context
- Subnet Abuse Density: 0.7852 (High Abuse Classification)
- Threat Siblings: 201 malicious IPs identified within 54.39.210.0/24
- Active Siblings: 173 currently active
- Neighbor Risk Distribution: 100 medium-risk neighbors, 0 high-risk neighbors
## DNS Infrastructure
- PTR Record: proxy-ca007-san23.ahrefs.net
- Hosted Domain: ahrefs.net
- Reverse Resolution: Confirmed to ahrefs.net infrastructure
- Forward Resolution: Single hostname resolved
## Historical Analysis
- Observation Count: 25 signals tracked
- Recent Activity: Signals observed as recently as June 2026
- Operator Score: Minimal (0.087โ0.2174 range)
- Trend: No significant escalation or de-escalation pattern detected
## Control Plane Assessment
- Route Stability: False (changes detected)
- DNSSEC: Valid
- RPKI State: Not evaluated
- BGP Prefix: 54.39.0.0/16
## Recommended Actions
1. Monitor: Add to watchlist for traffic from this subnet due to high neighborhood abuse density
2. Block: No immediate blocking recommended; IP not flagged as known attacker
3. Investigate: Correlate with ahrefs.net infrastructure queries for potential abuse
4. Rule Priority: Low-medium; consider blocking if traffic shows malicious patterns
## Intelligence Notes
This IP belongs to OVH hosting infrastructure associated with ahrefs.net services. While the IP itself shows no active threat indicators, the subnet exhibits elevated abuse density with over 200 threat siblings. SOC teams should monitor traffic patterns rather than apply immediate blocking rules. The geolocation data shows RTT validation anomalies that may require further investigation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059686 |
| CIDR Block | 54.39.210.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca007-san23.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca007-san23.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 23% | 9 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:29 UTC |
| Last Seen | 2026-06-27 08:33:53 UTC |
| Profile Built | 2026-06-28 02:39:40 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 26 |
Full dossier details are available via our API.