## IP Intelligence Briefing: 54.39.89.117/32
Classification: MODERATE RISK (Score: 40/100)
Date of Analysis: 2026-06-21
Intel Source: IPDebrief Platform
Ownership and Infrastructure
- ASN: 16276 (OVH SAS)
- Organization: Dmytro, Ahrefs Pte Ltd
- Netname: OVH-CUST-281059691
- Infrastructure: CloudCompute (OVH Hosting)
- Network Role: Cloud hosting provider with firewalled/no services configuration
Geolocation and Network Assignment
- Country: Canada (CA)
- Region: Quebec (QC)
- City: Beauharnois
- Geolocation Confidence: Low (0.18) โ RTT violation indicates 5628.6km distance from probe location with 27ms latency vs. minimum possible 112.6ms
- CIDR Block: 54.39.89.0/24
DNS and Service Profile
- PTR Hostname: proxy-ca012-san117.ahrefs.net
- Domain: ahrefs.net
- Forward Resolution: Confirmed
- Open Ports: None detected
- Services: No active services (firewalled configuration)
- TLS Certificate: Not available
Threat Indicators and Reputation
- Risk Score: 40 (Moderate)
- Blacklist Count: 0
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Abuse Confidence Score: Not assigned
- DNSBL Listings: 1 of 8 total lists
Subnet Context (54.39.89.0/24)
- Abuse Density: 0.8164 (High Abuse Classification)
- Total Siblings: 256
- Active Siblings: 178
- Threat Siblings: 209
- Neighbor Risk Distribution: 100 medium risk, 0 high risk, 0 low risk
- Inherited Risk: 32
Observation History
- Total Observations: 21 signals
- Recent Activity: Signals recorded 2026-06-21
- Persistence: Not persistently malicious
- Threat Observation Count: 1
- Ownership Changes: 0
Network Relationships
- Primary Network: OVH-CUST-281059691 (27 same-network relationships)
- DNS Associations: proxy-ca012-san117.ahrefs.net (13 relationships)
- External Organizations: None identified beyond hosting provider
Recommended Actions
SOC Analyst Guidance:
- Action Level: Monitor
- Block Recommendation: Not recommended at this time
- Rationale: Moderate risk score driven primarily by subnet-level abuse density (0.8164) rather than IP-specific malicious indicators. No direct threat indicators (blacklists, known attacks, spam sources). IP is cloud-hosted with no open services.
Firewall Considerations:
- No actionable firewall rules generated due to absence of active threat indicators
- Subnet context suggests elevated risk environment โ monitor for anomalous outbound connections
- DNS association with ahrefs.net indicates legitimate search engine marketing infrastructure
Risk Assessment Summary
The IP address 54.39.89.117 exhibits moderate risk primarily due to its association with a high-abuse density subnet (54.39.89.0/24). The IP itself shows no direct malicious indicators and is configured as a cloud-hosting resource with no open services. The geolocation confidence is low, which may impact threat attribution. SOC teams should monitor but not proactively block unless additional context indicates malicious activity from this IP or subnet.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059691 |
| CIDR Block | 54.39.89.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca012-san117.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca012-san117.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 22% | 1 | 3 |
| geolocation | 24% | 2 | 3 |
| Overall | 20% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-30 06:23:16 UTC |
| Last Seen | 2026-06-29 07:24:57 UTC |
| Profile Built | 2026-06-29 07:33:22 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.