# IP Intelligence Briefing: 54.39.6.122/32
Classification: Moderate Risk Cloud Infrastructure | Date Generated: 2026-06-20
## Executive Summary
IP 54.39.6.122 is an OVH cloud computing host located in Beaucharnois, Quebec, Canada. The address resolves to Ahrefs (proxy-ca001-san122.ahrefs.net) and operates under organization "Dmytro, Ahrefs Pte Ltd" (ASN 16276). While the IP shows no direct threat indicators, the /24 subnet exhibits elevated abuse density at 60.16%, requiring contextual monitoring.
## Risk Assessment
- Overall Risk Score: 40 (Moderate Risk)
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
- DNSBL Status: Listed on 1 of 8 total blacklists
## Infrastructure Profile
- ASN: 16276 (OVH)
- Organization: Dmytro, Ahrefs Pte Ltd
- Network Block: 54.39.6.0/24
- Location: Beaucharnois, QC, Canada
- Infrastructure Type: CloudCompute
- Connection Type: Firewalled / No Services
- Mobile/Residential: No
## DNS Resolution
- Primary Hostname: proxy-ca001-san122.ahrefs.net
- Forward Confirmed: No
- PTR Records: proxy-ca001-san122.ahrefs.net
- Email Authentication: SPF and DMARC not configured
- Forward Resolution Count: 1
## Neighborhood Analysis (54.39.6.0/24)
- Total Siblings: 256
- Active Siblings: 168
- Threat Siblings: 154
- Abuse Density: 60.16% (High Abuse Classification)
- Inherited Risk Score: 24
- Risk Distribution: 100 medium-risk neighbors, 0 high/low risk
## Observation History
- Total Observations: 24 signals
- Most Recent: 2026-06-20T08:37:35
- Threat Persistence: 0 days
- Campaign Matches: None
- Provider Stability: Consistent OVH cloud hosting profile across all observations
## Threat Indicators
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Likelihood: None
- Cert Matches: 0
- Banner Matches: 0
## Recommended Actions
- Monitoring Priority: Medium (due to neighborhood abuse density)
- Firewall Rules: No immediate blocking required; monitor for anomalous traffic patterns
- Reputation Watch: Track DNSBL status changes; currently listed on 1 of 8 lists
- Context: Legitimate cloud infrastructure with elevated neighborhood risk
## Intelligence Context
The IP represents legitimate cloud hosting infrastructure for Ahrefs, a web analytics and SEO tools provider. However, the /24 subnet's high abuse density (60.16%) suggests potential neighbor IP misuse. SOC teams should monitor for traffic patterns that deviate from expected web traffic profiles while maintaining awareness of the subnet's abuse context. No direct malicious activity was observed on this specific IP.
---
*Intel generated from IPDebrief platform data. For additional context, review related IPs in the 54.39.6.0/24 subnet.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059680 |
| CIDR Block | 54.39.6.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca001-san122.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca001-san122.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 20% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 22% | 3 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 23% | 12 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 23:50:47 UTC |
| Last Seen | 2026-06-28 10:45:14 UTC |
| Profile Built | 2026-06-29 04:51:01 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 27 |
Full dossier details are available via our API.