IP Intelligence Briefing: 54.39.6.218
Date: 2026-06-15
---
**1. IP Profile**
- Risk Score: 40 (Moderate Risk)
- Ownership:
- ASN: 16276 (OVH)
- Organization: Dmytro, Ahrefs Pte Ltd
- Network: OVH-CUST-281059680
- Geolocation:
- Country: Canada (QC, Beauharnois)
- Coordinates: Latitude 56.13, Longitude -106.35 (approximate)
- Threat Indicators:
- No active threats, malicious campaigns, or DNS blacklists detected.
- Not a Tor exit node, spam source, or known attacker.
---
**2. Network Context**
- Cloud Hosting:
- Part of OVH's cloud infrastructure (OVH-CUST-281059680).
- Classified as a CloudCompute instance with high_abuse subnet classification.
- Subnet Analysis:
- /24 Subnet: 54.39.6.0/24
- Abuse Density: 52.76% (high-risk subnet).
- Neighbor Risk: 100 IPs in subnet, 134 flagged as threats (medium/high risk).
- Inherited Risk: 21 (moderate).
---
**3. DNS & Services**
- DNS Associations:
- Linked to `proxy-ca001-san218.ahrefs.net` (Ahrefs, SEO tool provider).
- No SPF/DKIM records detected; DNSSEC validated.
- Services:
- No open ports or TLS services detected.
- No HTTP server banners or SSL certificates.
---
**4. Temporal Trends**
- Observation History:
- First recorded: 2026-06-09.
- Recent activity: 2026-06-15.
- No significant changes in risk scores or threat indicators.
- Subnet abuse density increased to high.
---
**5. Relationships**
- Network Connections:
- Directly linked to OVH-CUST-281059680 (same network).
- No direct links to other IPs or organizations.
- DNS Hostnames:
- Associated with Ahrefs' internal proxy (`proxy-ca001-san218.ahrefs.net`).
---
**6. Recommendations**
- Monitor Subnet:
- The 54.39.6.0/24 subnet has a high abuse density (52.76%). Investigate neighbor IPs for potential malicious activity.
- Verify Ahrefs Usage:
- Confirm if the Ahrefs proxy is legitimate or being used for unauthorized purposes.
- Block/Restrict Subnet:
- Consider blocking the entire subnet or implementing strict access controls due to its high-risk classification.
- Check for Compromise:
- No direct threats detected, but the subnet's abuse history suggests potential vulnerabilities.
---
Conclusion:
The IP 54.39.6.218 is a legitimate OVH-hosted cloud instance with no direct malicious activity. However, its subnet (54.39.6.0/24) is part of a high-abuse network, requiring heightened monitoring. SOC teams should prioritize investigating neighboring IPs and ensuring the Ahrefs proxy is not being misused.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059680 |
| CIDR Block | 54.39.6.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca001-san218.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca001-san218.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 22% | 10 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 03:10:36 UTC |
| Last Seen | 2026-06-28 18:04:25 UTC |
| Profile Built | 2026-06-29 06:07:54 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.