# IP Intelligence Briefing: 54.39.6.216/32
## Executive Summary
IP address 54.39.6.216 is a moderate-risk (40/100) cloud hosting endpoint assigned to OVH network OVH-CUST-281059680 under organization Dmytro, Ahrefs Pte Ltd. The IP is hosted in Beauharnois, QC, Canada but exhibits significant geolocation inconsistencies. The subnet demonstrates high abuse density (0.6523), with 65% of active sibling IPs flagged as threats, warranting defensive monitoring and recommended blocking.
## Profile Details
| Attribute | Value |
|---|---|
| **Risk Score** | 40 (Moderate) |
| **ASN** | 16276 |
| **Organization** | Dmytro, Ahrefs Pte Ltd |
| **Network** | OVH-CUST-281059680 |
| **CIDR Block** | 54.39.6.0/24 |
| **Infrastructure Type** | CloudCompute |
| **Provider** | OVH |
## Geographic Analysis
Location: Beauharnois, QC, Canada (Claimed)
Geolocation Validity: Invalid
Issue: RTT measurements indicate 5628.6 km distance from probe with 24ms observed RTT, but minimum possible RTT for this distance is 112.6ms. This discrepancy indicates the IP is not physically located in the claimed geolocation.
Control Plane: Route stability flag is false; DNSSEC valid; 1 DNSBL listing detected out of 8 total checks.
## DNS & Network Services
- PTR Record: proxy-ca001-san216.ahrefs.net
- Reverse DNS: Confirmed via forward resolution
- Associated Domain: ahrefs.net
- Services: No open ports detected; no TLS certificates; no HTTP services responding
- Forward Confirmed: False
## Threat Intelligence
| Indicator | Status |
|---|---|
| Blacklist Count | 0 |
| DNSBL Listings | 1 (of 8) |
| Tor Exit Node | No |
| Known Attacker | No |
| Spam Source | No |
| Abuse Confidence | Not scored |
| Operator Score | 0.2174 (Minimal) |
## Neighborhood Risk Assessment
The /24 subnet 54.39.6.0/24 exhibits elevated threat characteristics:
- Abuse Density: 0.6523 (High)
- Classification: high_abuse
- Total Siblings: 256
- Active Siblings: 170
- Threat Siblings: 167 (65% threat rate)
- Inherited Risk: 26
## Historical Observations
Analysis of 22 signal observations reveals:
- Recent blacklist activity with maximum severity rated "high"
- Persistent geolocation inconsistencies across multiple probes
- Consistent high-abuse subnet classification
- Minimal operator score persisting over observation period
## Recommended Actions
Based on risk profile and neighborhood context, the following firewall rules are recommended:
| Platform | Rule |
|---|---|
| **iptables** | `iptables -A INPUT -s 54.39.6.216 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 54.39.6.216 drop` |
| **nginx** | `deny 54.39.6.216;` |
| **pfSense** | `54.39.6.216/32` |
| **Cloudflare WAF** | Block with expression: `ip.src eq 54.39.6.216` |
| **AWS WAF** | Add address: `54.39.6.216/32` |
## Intelligence Assessment
The IP belongs to legitimate infrastructure (Ahrefs domain) but operates within a high-abuse hosting block. The combination of geolocation spoofing, DNSBL listings, and 65% sibling threat rate suggests this endpoint may be compromised or co-hosted with malicious actors. The lack of open services indicates the IP may be dormant or behind firewall protection.
Recommended SOC Action: Monitor inbound traffic from this IP for suspicious patterns. Apply blocking rules at perimeter defenses. Correlate with other indicators from the 54.39.6.0/24 subnet for additional context.
---
*Generated by IPDebrief Intelligence Analysis*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059680 |
| CIDR Block | 54.39.6.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca001-san216.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca001-san216.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-23 12:24:29 UTC |
| Last Seen | 2026-06-28 22:04:08 UTC |
| Profile Built | 2026-06-29 10:09:30 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.