# IP Intelligence Briefing: 54.39.6.180/32
## Executive Summary
IP 54.39.6.180 presents a Moderate Risk (40) profile associated with OVH cloud infrastructure. The address belongs to subnet 54.39.6.0/24 classified as high_abuse with 62.5% abuse density. Current services show no open ports or active listening services.
## Network Classification & Ownership
- ASN: 16276 (OVH SAS)
- Organization: Dmytro, Ahrefs Pte Ltd
- Network Block: 54.39.6.0/24
- Infrastructure Type: CloudCompute
- Status: Firewalled / No Services detected
- Registration: RIR: ARIN
## Geolocation Analysis
- Reported Location: Beaucharnois, QC, Canada
- RTT Validation: Violation detected. Measured RTT: 27ms vs minimum possible 112.6ms for reported distance (5,629km). GEOPLAUSIBLE flag: FALSE
- Probe Count: 5 probes across multiple signal types
## Threat Indicators
- Blacklist Count: 0
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Abuse Confidence Score: Not reported
## DNS & Service Analysis
- PTR Record: proxy-ca001-san180.ahrefs.net
- Domain: ahrefs.net
- Forward Resolution: 1 hostname confirmed
- Email Auth: SPF: No, DMARC: No
- HTTP Services: None detected (firewalled)
## Neighborhood Risk Profile
- Total Siblings: 256 IPs in /24 subnet
- Active Siblings: 174
- Threat Siblings: 160
- Abuse Density: 0.625 (High)
- Inherited Risk: 25
- Risk Distribution: 100 medium-risk neighbors, 0 high/low risk
## Historical Signal Observations
- Total Observations: 22
- Last Observation: 2026-06-18
- Ownership Changes: 0
- Threat Persistence: 0 days
- Operator Score: 0.2174 (Minimal)
- Network Classification: Consistently classified as high_abuse subnet
## Related Entities
- 50 relationships identified
- Primary association: OVH-CUST-281059680 network
- Multiple network-level relationships to same infrastructure
## Recommended Actions
- Monitor subnet-level activity for coordinated abuse patterns
- Consider blocking or rate-limiting traffic from subnet 54.39.6.0/24 due to high abuse density
- No immediate firewall rules required for this specific IP given moderate risk classification and lack of active services
- Correlate with ahrefs.net domain activity if applicable to investigation scope
## Risk Assessment
This IP represents a moderate-risk cloud-hosted address within a high-abuse OVH subnet. The geolocation discrepancy suggests possible misreporting or compromised infrastructure. While no immediate threats are associated with this specific address, the subnet context warrants defensive monitoring. The absence of open services and known threat indicators reduces immediate concern, but continued observation is recommended given the neighborhood's abuse density.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059680 |
| CIDR Block | 54.39.6.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca001-san180.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca001-san180.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 21% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:29 UTC |
| Last Seen | 2026-06-27 08:40:46 UTC |
| Profile Built | 2026-06-28 02:46:34 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 28 |
Full dossier details are available via our API.