IP Intelligence Briefing: 54.39.6.137
Date: 2026-06-09
---
**1. Core Profile**
- Risk Score: 40 (Moderate Risk)
- Ownership: Registered to Ahrefs Pte Ltd (OVH ASN 16276), classified as a cloud hosting provider.
- Geolocation:
- Country: Canada (QC, Beauharnois)
- Geo Validation: Implausible (RTT of 27ms inconsistent with 5629km distance).
- Network Role:
- Hosting: Yes (OVH CloudCompute)
- Subnet: 54.39.6.0/24 (OVH-CUST-281059680)
- Abuse Density: 52.76% (high abuse classification).
---
**2. Threat & Activity**
- Threat Indicators:
- No direct malicious indicators (no spam, attacks, or blacklists).
- DNS Association: Linked to proxy-ca001-san137.ahrefs.net (hostname).
- Neighborhood Risk:
- Subnet Threat Siblings: 134/254 IPs flagged as threats.
- Abuse Density: 52.76% (high abuse classification).
- Inherited Risk: 21 (moderate).
---
**3. Observation History**
- Recent Activity (Last 30 Days):
- DNS resolution for ahrefs.net (CAA records confirmed).
- Subnet abuse density analysis (high risk).
- DNSBL listings (1/8 total lists, severity: high).
- Geo validation anomalies (RTT inconsistency).
---
**4. Relationships**
- Network Links:
- Same network: OVH-CUST-281059680 (54.39.6.0/24).
- DNS associations: proxy-ca001-san137.ahrefs.net (multiple resolved).
- Hosting Context:
- Likely part of a cloud-hosted infrastructure (OVH).
---
**5. Recommendations**
- Monitor Subnet: The 54.39.6.0/24 subnet has high abuse density; investigate potential lateral movement or compromised hosts.
- Validate Geolocation: The IPβs low RTT (27ms) contradicts its claimed location in Canada. Verify if itβs a spoofed or residential IP.
- Inspect DNS Hostname: Analyze proxy-ca001-san137.ahrefs.net for malicious activity (e.g., C2 servers, data exfiltration).
- Check Neighbors: 134/254 IPs in the subnet are flagged as threats. Prioritize monitoring or blocking high-risk siblings.
---
Conclusion:
While 54.39.6.137 itself shows no direct malicious indicators, its association with a high-abuse subnet and geo validation anomalies warrants further investigation. The IPβs hosting context and DNS relationships suggest it could be part of a broader network with potential risks. SOC teams should correlate this data with internal logs and threat feeds to assess deeper compromise risks.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059680 |
| CIDR Block | 54.39.6.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca001-san137.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca001-san137.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 49% | 2 | 5 |
| routing | 27% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 35% | 3 | 4 |
| reputation | 31% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 33% | 12 | 20 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-21 21:01:08 UTC |
| Last Seen | 2026-06-28 16:44:37 UTC |
| Profile Built | 2026-06-29 10:50:00 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 30 |
Full dossier details are available via our API.