# IP INTELLIGENCE BRIEFING
Target IP: 54.39.210.230/32
Classification: Moderate Risk / High-Abuse Subnet
Date: Current
Analyst: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
IP 54.39.210.230 presents a moderate-risk profile (risk score: 40) within a high-abuse OVH hosting infrastructure. The /24 subnet (54.39.210.0/24) exhibits elevated abuse density (0.7969) with 204 threat siblings identified. No active threat indicators or malicious campaigns detected. Recommended for defensive blocking with contextual review.
---
## OWNERSHIP & INFRASTRUCTURE
- ASN: 16276 (OVH SAS)
- Organization: Dmytro, Ahrefs Pte Ltd
- Network Name: OVH-CUST-281059686
- CIDR Block: 54.39.210.0/24
- RIR: ARIN
- Infrastructure Type: Cloud Hosting
- Service Status: Firewalled / No Open Services
---
## GEOGRAPHIC ANALYSIS
- Reported Location: Beauharnois, QC, CA (Canada)
- Geographic Validation: FAILED
- RTT validation shows 26ms minimum, but 5629km distance from probe location would require minimum 112.6ms RTT
- Geo source count: 1 (consensus: true)
- GeoPlausible: false
- Implication: Reported geolocation may be inaccurate; RTT-based location suggests different physical location
---
## THREAT ASSESSMENT
- Overall Risk Score: 40 (Moderate)
- Abuse Confidence Score: Not available
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 total lists
- Threat Indicators: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Known Campaigns: None identified
---
## NEIGHBORHOOD ANALYSIS (54.39.210.0/24)
- Abuse Density: 0.7969 (High)
- Total Siblings: 256
- Active Siblings: 178
- Threat Siblings: 204
- Inherited Risk Score: 31
- Subnet Classification: High Abuse
- Risk Distribution: 100 medium-risk neighbors, 0 high-risk, 0 low-risk
This subnet demonstrates concentrated abuse activity, with 79.69% of IPs flagged as threats.
---
## OBSERVATION HISTORY
- Total Signals Observed: 24
- Latest Observation: 2026-06-20T15:02:16Z
- Key Signal Types:
- ASN allocation data (OVH SAS, age: 9256 days)
- BGP routing (AS Path: 1403 16276)
- Subnet abuse density (0.7969, high_abuse classification)
- Geolocation probes (confidence: 0.175โ0.95)
- Threat Persistence: 0 days (not persistently malicious)
---
## RELATIONSHIP GRAPH
- Total Relationships: 44
- Primary Relationship Type: Same Network (OVH-CUST-281059686)
- Associated Entities: Multiple network-level relationships with OVH infrastructure
---
## DNS ANALYSIS
- PTR Hostnames: proxy-ca007-san230.ahrefs.net
- Forward Resolution: proxy-ca007-san230.ahrefs.net (1 record)
- Reverse Confirmation: Not confirmed
- Email Authentication: SPF/DMARC not configured
- Associated Domain: ahrefs.net
- Implication: IP hosts legitimate Ahrefs infrastructure
---
## NETWORK SERVICES
- Open Ports: None detected
- TLS Certificate: None
- HTTP Title: None
- Server Banner: None
- Status: Fully firewalled
---
## CONTROL PLANE
- Origin ASN: 16276
- BGP Prefix: 54.39.0.0/16
- AS Path: 1403 16276
- RPKI State: Not available
- IRR Consistency: Not available
- Route Stability: Stable (route changes: 0 in 30 days)
- DNSSEC Valid: true
- HAS CAA: true
---
## RECOMMENDED ACTIONS
Risk-Based Recommendation: Block with contextual awareness
| Platform | Firewall Rule |
|---|---|
| **iptables** | `iptables -A INPUT -s 54.39.210.230 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 54.39.210.230 drop` |
| **nginx** | `deny 54.39.210.230;` |
| **pfSense** | `54.39.210.230/32` |
| **Cloudflare WAF** | `Block 54.39.210.230 โ IPDebrief risk score 40` |
| **AWS WAF** | `Addresses: 54.39.210.230/32, Description: IPDebrief risk 40` |
Action Notes:
- No specific threat indicators detected
- High-abuse subnet context warrants consideration
- Legitimate Ahrefs infrastructure association
- Consider whitelist if traffic is expected from this IP
---
## INTELLIGENCE CONCLUSION
IP 54.39.210.230 operates within OVH hosting infrastructure associated with Ahrefs Pte Ltd. While no direct threat indicators are present, the subnet exhibits high abuse density with 79.69% of sibling IPs flagged as threats. The IP is currently firewalled with no open services. Defensive blocking is recommended due to neighborhood risk profile, though the legitimate business association should be considered in incident response contexts. No immediate malware or attack activity detected.
---
*Report generated by IPDebrief Intelligence Platform. Data based on observed signals and threat intelligence feeds.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059686 |
| CIDR Block | 54.39.210.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca007-san230.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca007-san230.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 37% | 3 | 5 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 29% | 12 | 20 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 21:01:08 UTC |
| Last Seen | 2026-06-28 16:41:59 UTC |
| Profile Built | 2026-06-29 10:47:42 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 30 |
Full dossier details are available via our API.