IP INTELLIGENCE BRIEFING: 54.39.6.187/32
Classification: Moderate Risk
Date: June 19, 2026
---
EXECUTIVE SUMMARY
IP address 54.39.6.187 is a moderate-risk (score: 40/100) cloud infrastructure endpoint associated with Ahrefs Pte Ltd, hosted on OVH (ASN 16276) infrastructure in Beauharnois, Quebec, Canada. The IP resolves to proxy-ca001-san187.ahrefs.net and operates as a firewalled cloud compute instance with no detected open services. The subnet exhibits elevated abuse density (0.668) with 171 threat-sibling IPs out of 256 total neighbors.
OWNERSHIP AND INFRASTRUCTURE
- Organization: Dmytro, Ahrefs Pte Ltd
- ASN: 16276 (OVH SAS)
- CIDR Block: 54.39.6.0/24
- Infrastructure Type: Cloud Compute
- Network Role: Cloud hosting provider environment
- Geolocation: Beauharnois, Quebec, Canada (reported)
DNS AND SERVICE ANALYSIS
The IP forwards to proxy-ca001-san187.ahrefs.net with one forward resolution confirmed. No open ports, TLS certificates, or HTTP services detected. The PTR record indicates Ahrefs proxy infrastructure. Email authentication (SPF/DMARC) is not configured for the domain.
THREAT INDICATORS
- Abuse Confidence: Not applicable (null)
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 total lists
- Campaign Correlation: None detected
CONTROL PLANE AND ROUTING
- BGP Prefix: 54.39.0.0/16
- Route Stability: Unstable
- Operator Score: 0.2174 (Minimal)
- DNSSEC: Valid
- CAA Records: Present
SUBNET ANALYSIS (54.39.6.0/24)
- Abuse Density: 0.668 (High Abuse)
- Classification: High Abuse
- Active Siblings: 182 of 256 IPs
- Threat Siblings: 171 IPs
- Risk Distribution: 53 medium risk, 47 low risk, 0 high risk neighbors
- Inherited Risk: 26
OBSERVATION HISTORY
Analysis reveals 19 historical observations. Recent data from June 19, 2026 confirms:
- Consistent subnet abuse density (0.668)
- ASN AS16276 OVH SAS association
- Geographic placement in Beauharnois, QC
- Two threat pulses detected
- Operator score maintained at minimal (0.2174)
One observation from June 14, 2026, flagged a geographic inconsistency, reporting coordinates in northern Canada (56.13°N, -106.35°W) with an RTT violation of 5628.6km versus a minimum possible 112.6ms.
RELATIONSHIP GRAPH
Fifty relationships detected, primarily same-network associations to OVH-CUST-281059680. No significant external entity correlations beyond the hosting infrastructure.
RECOMMENDED ACTIONS
- No immediate firewall actions recommended based on current risk profile
- Monitor subnet 54.39.6.0/24 for elevated activity due to high abuse density (0.668)
- No evidence of active malicious campaigns or known threat actor attribution
ASSIGNMENT NOTES
The IP operates as legitimate proxy infrastructure for Ahrefs SEO tools. Risk score of 40 reflects moderate classification driven by subnet-level abuse density rather than individual IP malicious activity. No positive threat indicators or blacklistings detected.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059680 |
| CIDR Block | 54.39.6.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca001-san187.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca001-san187.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 22% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 21% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-12 15:48:25 UTC |
| Last Seen | 2026-06-27 21:51:42 UTC |
| Profile Built | 2026-06-28 15:56:56 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.