# IP Intelligence Briefing: 54.39.6.110/32
Classification: Low Risk - Cloud Infrastructure Node
Date: Intelligence compiled from current IPDebrief analysis
## Executive Summary
IP 54.39.6.110 was identified as a low-risk cloud infrastructure endpoint belonging to Ahrefs Pte Ltd, hosted on OVH infrastructure. The IP maintains a risk score of 25/100 with minimal threat indicators. No active malicious campaigns or known attacker associations were detected.
## Ownership and Network Profile
The IP address was registered to "Dmytro, Ahrefs Pte Ltd" under ASN 16276 (OVH). Network classification confirmed cloud hosting infrastructure with CIDR block 54.39.6.0/24. Geographic analysis placed the endpoint in Beauharnois, Quebec, Canada (CA).
DNS reverse resolution identified the hostname "proxy-ca001-san110.ahrefs.net" with domain ahrefs.net. No forward confirmation was available. Email authentication records (SPF, DMARC) were not configured for the associated domain.
## Risk Assessment
Current risk evaluation showed a score of 25/100, classified as "Low Risk." Threat indicators were absent, with zero known blacklist entries and no associations with known attack campaigns. The operator score registered at 0.2174, labeled "Minimal."
DNSBL analysis revealed one listing across eight total lists, suggesting historical or minor reputation issues. No Tor exit node, VPN, proxy, or residential traffic was detected.
## Neighborhood Context
The /24 subnet (54.39.6.0/24) showed mixed classification with an abuse density of 0.4375. Analysis of 256 total siblings identified 208 active addresses, with 112 classified as threat siblings and 53 as medium-risk. The target IP's neighborhood inherited risk score of 17.
Risk distribution across neighbors showed: 0 high-risk, 53 medium-risk, and 47 low-risk addresses.
## Service and Port Analysis
Network scanning detected no open ports, TLS certificates, HTTP titles, or service banners. The endpoint was classified as "Firewalled / No Services," indicating it operates as a passive infrastructure node rather than an active service endpoint.
## Historical Observations
Analysis of 24 signal observations from 2026 showed consistent network behavior patterns. Recent observations (June 2026) maintained stable risk profiles with no significant escalation. Signal types included threat, routing, services, ownership, reputation, and geolocation assessments.
## Related Entities
Relationship mapping identified 62 connections, primarily network-based relationships to OVH-CUST-281059680. No external hostname, organization, or certificate relationships beyond the parent network were identified.
## Recommended Actions
No specific security actions or firewall rules were generated due to the low-risk classification. The IP requires monitoring as part of normal cloud infrastructure management but does not warrant immediate blocking or investigation.
## Conclusion
IP 54.39.6.110 represents a legitimate cloud hosting endpoint for Ahrefs operations on OVH infrastructure. The absence of active threat indicators, combined with stable historical observations and low-risk classification, supports continued monitoring without immediate remediation action.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059680 |
| CIDR Block | 54.39.6.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca001-san110.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca001-san110.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 15% | 2 | 2 |
| reputation | 27% | 1 | 3 |
| geolocation | 20% | 2 | 2 |
| Overall | 20% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-10 16:14:42 UTC |
| Last Seen | 2026-06-27 18:10:43 UTC |
| Profile Built | 2026-06-28 18:15:10 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 29 |
Full dossier details are available via our API.