IP Intelligence Briefing: 54.39.6.178
*Generated via IPDebrief Threat Intelligence Platform*
---
**1. Core Profile**
- Risk Score: 50 (Moderate Risk)
- Owner: Dmytro, Ahrefs Pte Ltd (OVH ASN 16276)
- Geolocation:
- Country: Canada (CA)
- City: Singapore (inferred, may be inaccurate)
- Subnet: 54.39.6.0/24 (OVH-CUST-281059680)
- Network Role: Cloud Compute (OVH infrastructure, no public services detected)
- Threat Indicators: No malicious activity detected (no abuse confidence, no blacklists, no campaigns).
---
**2. Historical Observations**
- Stability: No significant changes in risk signals over time.
- Abuse Density: Subnet has 51.43% abuse density (high_abuse classification), with 126 threat siblings (141 active IPs in subnet).
- Ownership: Stable (0 ownership changes).
---
**3. Relationships & Dependencies**
- DNS: Linked to `proxy-ca001-san178.ahrefs.net` (Ahrefs infrastructure).
- Network: Part of OVHโs 54.39.6.0/24 subnet (245 total IPs, 141 active).
- Routing: BGP prefix `54.39.0.0/16`, route stability: unstable (route changes in last 30 days).
- DNSSEC: Valid; CAA records present.
---
**4. Neighborhood Analysis**
- Subnet Risk: High abuse density (0.5143), inherited risk: 20.
- Neighbors:
- 100 IPs in 54.39.6.0/24.
- 79 medium-risk and 21 low-risk siblings.
- No direct malicious neighbors, but subnet-wide risk suggests potential association with malicious activity.
---
**5. Recommendations**
- Monitor Subnet: High abuse density warrants closer scrutiny of traffic patterns.
- Verify Geolocation: Discrepancy between Canada (country code) and Singapore (city) requires validation.
- Block High-Risk Neighbors: Consider isolating IPs with high risk scores in the subnet.
- Check Hostname: Investigate `proxy-ca001-san178.ahrefs.net` for any historical malicious activity.
---
Conclusion: 54.39.6.178 appears to be a legitimate cloud compute resource (Ahrefs), but its subnet exhibits elevated abuse density. SOC teams should prioritize monitoring subnet traffic and validating geolocation data to mitigate potential risks.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059680 |
| CIDR Block | 54.39.6.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca001-san178.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca001-san178.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 32% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 22% | 9 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-26 00:51:02 UTC |
| Last Seen | 2026-06-29 02:35:30 UTC |
| Profile Built | 2026-06-29 08:37:35 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.