# IP INTELLIGENCE BRIEFING
## Target: 54.39.210.29/32
EXECUTIVE SUMMARY
IP address 54.39.210.29 is a moderate-risk (40/100) cloud hosting endpoint owned by OVH SAS (AS16276) located in Beaucharnois, Quebec, Canada. The IP shows high neighborhood abuse density and geolocation validation anomalies requiring SOC attention.
OWNERSHIP & INFRASTRUCTURE
- Provider: OVH (AS16276, OVH-CUST-281059686)
- Infrastructure Type: Cloud Computing (hosting)
- Network Classification: Cloud infrastructure with firewalled services
- Registration: ARIN, Canada
- Geolocation: Beaucharnois, QC, CA (3000km accuracy radius)
THREAT PROFILE
- Risk Score: 40 (Moderate Risk)
- Abuse Confidence: No active threat indicators currently flagged
- Blacklist Status: 0 active blacklists
- Known Campaigns: None identified
- Tor/Proxy Status: Not a Tor exit node, not known proxy
ANOMALIES & CONCERNS
Geolocation Validation Failure
- RTT validation failed: Measured 30-33ms vs. minimum possible 112.6ms for 5629km distance
- Multiple geolocation sources show conflicting data
- GeoPlausible flag: False
Neighborhood Risk Pattern
- Subnet 54.39.210.0/24 classified as HIGH_ABUSE
- Abuse density: 0.8008 (80% of IPs flagged)
- Threat siblings: 205 out of 256 total IPs
- All 100 sampled neighbors show riskScore 40
DNS Configuration Issues
- Forward resolution: proxy-ca007-san29.ahrefs.net
- No SPF/DMARC configured
- DNSSEC valid but operator score minimal (0.2174)
OBSERVATION HISTORY (Recent 20 Signals)
- June 28, 2026: Threat indicators detected (confidence 0.75)
- June 20, 2026: Multiple signals showing consistent CA geolocation with varying confidence
- Signal persistence: Single threat observation, not persistently malicious
- Ownership stability: No changes recorded
RELATIONSHIP NETWORK
- 36 total relationships identified
- Primary linkage: Same Network (OVH-CUST-281059686)
- 31+ duplicate network references indicating shared infrastructure
RECOMMENDED ACTIONS
Firewall/Blocking Rules
```bash
# iptables
iptables -A INPUT -s 54.39.210.29 -j DROP
# nftables
nft add rule inet filter input ip saddr 54.39.210.29 drop
# nginx
deny 54.39.210.29;
# Cloudflare WAF
Block 54.39.210.29 โ IPDebrief risk score 40
```
Monitoring Recommendations
1. Monitor for traffic patterns from this subnet (all /24 addresses show same risk score)
2. Investigate geolocation spoofing potential in outbound traffic
3. Review DNS query logs for ahrefs.net domain activity
4. Consider blocking entire /24 subnet due to 80% abuse density
RISK ASSESSMENT
This IP presents moderate risk with high neighborhood context. The geolocation anomaly and elevated subnet abuse rate suggest potential for abuse or compromised infrastructure. No active malicious indicators currently detected, but the neighborhood profile warrants defensive blocking and monitoring.
Classification: MODERATE RISK โ BLOCK AND MONITOR
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059686 |
| CIDR Block | 54.39.210.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca007-san29.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca007-san29.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 03:10:35 UTC |
| Last Seen | 2026-06-28 18:03:34 UTC |
| Profile Built | 2026-06-29 06:07:55 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.