IPDebrief

54.39.210.58

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING: 54.39.210.58/32

Date: 2026-06-21

Classification: MODERATE RISK

Risk Score: 40/100

Analyst: IPDebrief Intelligence Team

---

## EXECUTIVE SUMMARY

IP 54.39.210.58 is a cloud infrastructure endpoint hosted on OVH SAS in Quebec, Canada, associated with Ahrefs Pte Ltd. The IP demonstrates moderate risk (40/100) but operates within a /24 subnet exhibiting critically high abuse density (0.8008). The neighborhood contains 205 threat-identified siblings out of 206 active peers, indicating systematic abuse potential. Geolocation validation shows significant implausibility due to RTT discrepancies.

---

## OWNERSHIP & INFRASTRUCTURE

AttributeValue
**ASN**AS16276 (OVH SAS)
**Organization**Dmytro, Ahrefs Pte Ltd
**Network**OVH-CUST-281059686
**CIDR Block**54.39.210.0/24
**Registration**RIR: ARIN
**Infrastructure Type**CloudCompute / Hosting
**Connection Type**Firewalled / No Services

---

## GEOSPATIAL ANALYSIS

Claimed Location: Beauharnois, Quebec, Canada (45.3161°N, -73.8736°W)

Validation Status: โŒ INVALID

MetricObservedExpected
Distance from Probe5,628.6 kmโ€”
Minimum Possible RTT112.6 msโ€”
Observed RTT26.0 ms**ANOMALY**

*The observed RTT is 4.1× lower than physically possible for the claimed distance. Geolocation confidence is FALSE (geoPlausible: false).*

---

## THREAT INTELLIGENCE

Known Indicators

Neighborhood Risk Profile (54.39.210.0/24)

Assessment: The /24 subnet demonstrates systemic compromise. Nearly all active endpoints in the neighborhood are threat-identified, suggesting either:

1. Widespread legitimate abuse by the hosting provider

2. Compromised infrastructure at the provider level

3. Legitimate hosting with high abuse potential

---

## DNS & HOSTNAMES

PTR Record: proxy-ca007-san58.ahrefs.net

Forward Resolution: proxy-ca007-san58.ahrefs.net (1 record)

Hosted Domains: None detected

Assessment: DNS configuration indicates legitimate infrastructure naming (proxy-ca007-san58.ahrefs.net), but the hostname suggests proxy/forwarding functionality.

---

## OBSERVATION HISTORY

Recent Signals (2026-06-21):

Temporal Trends:

---

## RECOMMENDED ACTIONS

Firewall Rules (Risk Score: 40)

iptables:

```bash

iptables -A INPUT -s 54.39.210.58 -j DROP

```

nftables:

```bash

nft add rule inet filter input ip saddr 54.39.210.58 drop

```

nginx:

```nginx

deny 54.39.210.58;

```

Platform-Specific Recommendations

Cloudflare WAF: Block IP (risk score 40)

AWS WAF: Add 54.39.210.58/32 to IP set for blocking

---

## SOC ANALYST DECISION MATRIX

ConditionRecommendation
**Traffic from 54.39.210.58**Review against threat intelligence
**High-volume inbound**Block or rate-limit
**Suspicious outbound**Block immediately
**Known-good traffic**Monitor and log

---

## INTELLIGENCE CONCLUSION

IP 54.39.210.58 presents moderate individual risk but operates within a high-abuse neighborhood (99.5% threat rate among active peers). The geolocation validation failure and single DNS blacklist listing suggest potential reputation compromise or infrastructure misuse. Given the systemic abuse in the /24 subnet, defensive blocking is recommended for inbound traffic. The infrastructure appears to be legitimate cloud hosting (Ahrefs), but the neighborhood abuse density warrants heightened scrutiny.

Priority: MEDIUM

Action Required: Monitor and consider blocking based on organizational risk tolerance

---

*Generated by IPDebrief Intelligence Platform*

*Data sources: IPDebrief, ProxyCheck, Cymru, AbuseIPDB, and multiple threat feeds*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡จ๐Ÿ‡ฆ Canada
RegionQC
CityBeauharnois
Timezoneโ€”
Latitude45.32
Longitude-73.87

๐Ÿข Ownership & Registration

OrganizationDmytro, Ahrefs Pte Ltd
ASNAS16276
Network NameOVH-CUST-281059686
CIDR Block54.39.210.0/24
RIRARIN
CountrySingapore
Abuse Contactโ€”

๐ŸŒ DNS Intelligence

PTRproxy-ca007-san58.ahrefs.net
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-ca007-san58.ahrefs.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
23
routing
8%
11
services
8%
11
ownership
19%
22
reputation
22%
13
geolocation
33%
24
Overall19%914
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Claimed geolocation contradicts RTT physics measurement

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-26 00:51:02 UTC
Last Seen2026-06-29 02:35:44 UTC
Profile Built2026-06-29 02:41:59 UTC
Data FreshnessLive
Signal Types22
Total Observations23
๐Ÿ” 22 signal types ยท 23 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.