IP Intelligence Briefing: 54.39.6.213
*Generated from IPDebrief analysis*
---
**1. Core Risk Profile**
- Risk Score: 40 (Moderate Risk)
- Ownership: Owned by OVH (ASN 16276), registered to Dmytro, Ahrefs Pte Ltd.
- Geolocation:
- Country: Canada (QC, Beauharnois)
- Plausibility: Low (RTT discrepancy: 27ms vs. expected 112.6ms for 5629km distance).
- Network Role: Cloud compute instance (OVH hosting). No open ports or TLS services detected.
- Threat Indicators: No direct malicious activity (no abuse confidence, spam, or known attacker flags).
---
**2. Neighborhood Analysis**
- Subnet: 54.39.6.0/24
- Abuse Density: 59.77% (high risk subnet).
- Neighbor Risk:
- 153 of 256 IPs in the subnet are flagged as threats.
- Neighboring IPs exhibit similar risk scores (40โ50).
- Inherited Risk: 23 (likely due to subnet-level abuse).
---
**3. Historical Observations (Last 28 Days)**
- First Observation: June 14, 2026.
- Key Signals:
- DNS resolution to `proxy-ca001-san213.ahrefs.net`.
- High abuse density in subnet (0.5977).
- Geolocation spoofing suspicion (RTT mismatch).
- No Persistent Threats: No repeated malicious signals or campaign correlations.
---
**4. Relationships & Context**
- Linked Entities:
- OVH-CUST-281059680 (same network).
- Domain: `ahrefs.net` (DNS resolver).
- Certificates: No TLS certificates detected.
- Email Reputation: No SPF/DKIM records found.
---
**5. Recommended Actions**
- Monitoring: Track activity in the 54.39.6.0/24 subnet due to high abuse density.
- Blocking: Consider blocking the IP if it exhibits unexpected traffic patterns.
- Firewall Rules (example):
```bash
iptables -A INPUT -s 54.39.6.213 -j DROP
nft add rule inet filter input ip saddr 54.39.6.213 drop
```
- Investigation: Verify geolocation spoofing and check for lateral movement within the subnet.
---
**6. Summary**
The IP is a cloud-hosted instance under OVH, linked to Ahrefs. While no direct malicious activity is detected, its location in a high-abuse subnet (54.39.6.0/24) raises concerns. Geolocation anomalies and inherited risk suggest potential spoofing or compromised infrastructure. SOC teams should monitor this subnet closely and apply blocking rules if further suspicious behavior is observed.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059680 |
| CIDR Block | 54.39.6.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca001-san213.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca001-san213.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:29 UTC |
| Last Seen | 2026-06-27 08:42:16 UTC |
| Profile Built | 2026-06-28 02:47:40 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 29 |
Full dossier details are available via our API.