IP INTELLIGENCE BRIEFING
Target: 54.39.210.233/32
Date: 2026-06-20
Analyst: IPDebrief Intelligence Division
---
**SUMMARY**
IP 54.39.210.233 is a Moderate Risk (Score: 40) residential/hosting cloud compute instance located in Beauharnois, QC, Canada. The IP resolves to Ahrefs infrastructure (proxy-ca007-san233.ahrefs.net) but operates within an OVH-hosted subnet exhibiting elevated abuse density.
---
**OWNERSHIP & NETWORK ROLE**
- Provider: OVH (ASN 16276)
- Organization: Dmytro, Ahrefs Pte Ltd
- Netname: OVH-CUST-281059686
- Infrastructure Type: CloudCompute, Hosting
- Geolocation: Canada, Quebec, Beauharnois
- DNS: proxy-ca007-san233.ahrefs.net (Ahrefs domain)
---
**THREAT PROFILE**
- Risk Score: 40 (Moderate Risk)
- Abuse Confidence: Not explicitly flagged as known attacker, spam source, or Tor exit node
- Blacklist Count: 0
- DNSBL Listings: 1 (of 8 total lists)
- Services: No open ports detected; classification indicates "Firewalled / No Services"
---
**SUBNET ANALYSIS (54.39.210.0/24)**
- Abuse Density: 0.793 (High Abuse Classification)
- Total Siblings: 256
- Active Siblings: 174
- Threat Siblings: 203
- Neighborhood Risk: 31 (Inherited Risk)
- Sampled Neighbors: 100 neighbors analyzed; all medium risk (Score: 40)
---
**OBSERVATION HISTORY**
Recent signals (2026-06-20) confirm:
- Network Classification: Cloud infrastructure (OVH) โ confidence 0.90
- Geolocation: Canada (confidence 0.35, accuracy ±3000km)
- Abuse Density: 0.793 (consistent across recent observations)
- Operator Score: 0.2174 (Minimal)
- Ownership Stability: No ownership changes observed
---
**RELATIONSHIPS**
- Same Network: OVH-CUST-281059686 (43 relationship records identified)
- Associated Domains: ahrefs.net
- Correlated Campaigns: None identified
---
**RECOMMENDED ACTIONS**
Despite no explicit threat indicators, the elevated neighborhood abuse density warrants defensive posture. Implement the following controls:
Firewall Rules:
- iptables: `iptables -A INPUT -s 54.39.210.233 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 54.39.210.233 drop`
- nginx: `deny 54.39.210.233;`
- pfSense: `54.39.210.233/32`
Cloud WAF:
- Cloudflare: Block IP (Expression: `ip.src eq 54.39.210.233`)
- AWS WAF: `Addresses: ["54.39.210.233/32"]`
---
**INTELLIGENCE JUDGMENT**
This IP presents a moderate-risk profile with no direct threat indicators. However, the subnet exhibits high abuse density (203 threat siblings in 256 total), suggesting systemic risk in the hosting environment. The association with Ahrefs infrastructure may indicate legitimate use, but the firewall rule recommendations suggest elevated risk. Monitor for behavioral changes and consider broader subnet-level blocking if abuse patterns correlate.
Recommendation: Implement blocking rules with observation; re-evaluate after 30 days based on continued traffic patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059686 |
| CIDR Block | 54.39.210.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca007-san233.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca007-san233.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 21% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 15:27:14 UTC |
| Last Seen | 2026-06-28 07:42:43 UTC |
| Profile Built | 2026-06-29 01:48:21 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.