## IP Intelligence Briefing: 54.39.210.238
Date: 2026-06-20
Classification: Moderate Risk
Risk Score: 40/100
Executive Summary
IP 54.39.210.238 is a moderate-risk address (risk score 40) associated with Ahrefs Pte Ltd, hosted on OVH infrastructure in Canada. The address resolves to a DNS hostname proxy-ca007-san238.ahrefs.net and is classified as high-abuse density within its /24 subnet. No active services or open ports were detected during probing.
Technical Profile
- ASN: 16276 (OVH)
- Organization: Dmytro, Ahrefs Pte Ltd (OVH-CUST-281059686)
- Geolocation: Beauharnois, Quebec, Canada (CA)
- Network Role: Cloud/Hosting infrastructure (isHosting: true)
- DNS Records: proxy-ca007-san238.ahrefs.net (ahrefs.net)
- Control Plane: 1 DNSBL listing across 8 total lists; RPKI state not available
Threat Indicators
- Abuse Confidence: Moderate risk classification
- Threat Feeds: No active threat feed matches in current profile
- Known Campaigns: None detected
- Blacklist Count: 0
- DNSBL Status: Listed on 1 of 8 monitored DNSBL feeds
- Campaign Likelihood: None
- Tor Exit: No
- Known Attacker: No
- Spam Source: No
Network Context
The /24 subnet (54.39.210.0/24) exhibits high abuse density (0.7812). Neighborhood analysis revealed 100 neighbor IPs with predominantly medium-risk scores (100 medium, 0 high, 0 low). The subnet contains 172 active siblings out of 256 total addresses, with 200 threat siblings identified in the control plane data. The IP is associated with network OVH-CUST-281059686 across 36 relationship records.
Behavioral History
Signal observation history contains 21 recorded observations. Recent activity includes:
- Domain resolution to ahrefs.net (confidence 0.80, observed 2026-06-20)
- Subnet abuse density classification as high_abuse (confidence 0.75, observed 2026-06-15)
- Geolocation signals from Alienvault-OTX indicating Quebec, Canada with threat presence (confidence 0.75)
- Operator score classified as "Minimal" (0.2174)
No ownership changes or persistent malicious behavior detected over the observation period.
Recommended Actions
Based on risk profile and control plane data, the following firewall rules are recommended:
iptables:
```
iptables -A INPUT -s 54.39.210.238 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 54.39.210.238 drop
```
nginx:
```
deny 54.39.210.238;
```
pfSense:
```
54.39.210.238/32
```
Cloudflare WAF:
```json
{"description":"Block 54.39.210.238 โ IPDebrief risk score 40","action":"block","filter":{"expression":"ip.src eq 54.39.210.238"}}
```
AWS WAF:
```json
{"Addresses":["54.39.210.238/32"],"Description":"IPDebrief risk 40"}
```
Analyst Notes
The IP resolves to a legitimate ahrefs.net hostname but operates within a high-abuse density OVH hosting subnet. The DNSBL listing indicates prior abuse activity. While no active malicious services were detected, the neighborhood context and control plane indicators warrant blocking as a precautionary measure. Correlate with internal logs to verify any observed traffic patterns before implementing final policy.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059686 |
| CIDR Block | 54.39.210.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca007-san238.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca007-san238.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 23% | 1 | 2 |
| geolocation | 19% | 2 | 2 |
| Overall | 20% | 10 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-25 06:42:31 UTC |
| Last Seen | 2026-06-29 01:24:57 UTC |
| Profile Built | 2026-06-29 07:26:26 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.