IP INTELLIGENCE BRIEFING: 54.39.6.143/32
EXECUTIVE SUMMARY
IP 54.39.6.143 presents moderate risk (score: 40) as OVH cloud hosting infrastructure. The IP resolves to ahrefs.net domain but operates with no active servicesβfirewalled with no open ports. While individual IP risk is moderate, the subnet 54.39.6.0/24 exhibits high abuse density (0.668), indicating significant neighborhood contamination.
OWNERSHIP & NETWORK CLASSIFICATION
- Provider: OVH (ASN: 16276)
- Organization: Dmytro, Ahrefs Pte Ltd
- CIDR Block: 54.39.6.0/24
- Infrastructure Type: Cloud/Hosting
- Service Status: Firewalled / No Services
- Network Role: Hosting provider with cloud compute capabilities
GEOLOCATION ANALYSIS
- Reported Location: Canada, Quebec, Beauharnois
- Geographic Validation: Flagged as implausible (geoPlausible: false)
- RTT Violation: 25.0ms observed vs. 112.6ms minimum required for reported distance (5,629 km)
- Confidence: Low confidence (0.30) on recent observations
THREAT INTELLIGENCE
- Threat Indicators: None detected
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Status: Listed on 1 of 8 DNSBL feeds
- Campaign Correlation: No matching campaigns detected
SUBNET CONTEXT (54.39.6.0/24)
- Abuse Density: 0.668 (high_abuse classification)
- Inherited Risk Score: 26
- Neighbor Analysis: 256 total IPs, 182 active, 171 with threat indicators
- Risk Distribution: 0 high-risk, 93 medium-risk, 7 low-risk neighbors
- Assessment: Subnet shows elevated abuse activity; individual IP risk may be influenced by neighborhood contamination
OBSERVATION HISTORY (22 RECORDS)
Recent signals indicate:
- Minimal operator score (0.2174)
- Stable cloud compute classification
- Persistent hosting infrastructure designation
- No escalation in threat severity
RECOMMENDED ACTIONS
| Platform | Action |
|---|---|
| iptables | `iptables -A INPUT -s 54.39.6.143 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 54.39.6.143 drop` |
| nginx | `deny 54.39.6.143;` |
| Cloudflare WAF | Block IP with expression: `ip.src eq 54.39.6.143` |
| AWS WAF | Add rule for address `54.39.6.143/32` |
ASSESSMENT
This IP is legitimate OVH hosting infrastructure but operates in a high-abuse subnet environment. The geolocation discrepancy warrants monitoring. Given the subnet's abuse density (0.668), blocking is recommended for inbound traffic protection. No active malicious indicators detected at the individual IP level, but neighborhood contamination suggests elevated risk.
CONFIDENCE LEVEL: Moderate
LAST UPDATED: Current analysis based on live intelligence feeds
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059680 |
| CIDR Block | 54.39.6.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca001-san143.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca001-san143.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 22% | 1 | 2 |
| geolocation | 31% | 2 | 3 |
| Overall | 20% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-10 10:13:59 UTC |
| Last Seen | 2026-06-27 17:38:19 UTC |
| Profile Built | 2026-06-28 11:43:56 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 26 |
Full dossier details are available via our API.