# IP Intelligence Briefing: 54.39.89.126
Classification: Moderate Risk / Cloud Infrastructure / OVH Hosting
---
## Executive Summary
IP 54.39.89.126 is a cloud compute address allocated to OVH under the customer block OVH-CUST-281059691. The address resolves to ahosted domain within the Ahrefs.net namespace but presents no active threat indicators. While the IP itself shows moderate risk (score 50), its neighborhood demonstrates elevated abuse density with 75.78% classification of high-abuse traffic.
---
## Network Ownership and Registration
| Attribute | Value |
|---|---|
| ASN | 16276 |
| Organization | Dmytro, Ahrefs Pte Ltd |
| Network Name | OVH-CUST-281059691 |
| CIDR Block | 54.39.89.0/24 |
| RIR | ARIN |
| Infrastructure Type | CloudCompute |
| Service Purpose | Firewalled / No Services |
---
## Geolocation Analysis
Stated Location: Canada (QC) - Beauharnois
Validation Status: โ ๏ธ GEOGRAPHIC DISCREPANCY DETECTED
* Distance Violation: 5,628.6 km from expected location
* RTT Violation: 27.0ms observed vs. 112.6ms minimum possible for 5,629 km distance
* GeoConsensus: True (1 source)
* GeoPlausible: False (validation failed)
The geolocation data indicates the IP is not actually located in the stated Canadian region.
---
## Threat Assessment
Current Risk Score: 50 (Moderate Risk)
Threat Indicators:
* Blacklist Count: 0
* Known Attacker: No
* Tor Exit Node: No
* Spam Source: No
* Known Campaigns: None correlated
* DNSBL Listed: 2 of 8 total lists
Network Role Classification:
* Provider: OVH
* Is Cloud: Yes
* Is Hosting: Yes
* Is CDN/VPN/Proxy: No
---
## DNS and Service Analysis
Forward Resolution: proxy-ca012-san126.ahrefs.net
PTR Hostname: proxy-ca012-san126.ahrefs.net
Associated Domain: ahrefs.net
Forward Resolution Confirmed: No
Service Status:
* Open Ports: None detected
* TLS Certificate: None
* HTTP Title: None
The IP resolves to an Ahrefs-hosted proxy node but shows no active service banners or open ports on current probe.
---
## Neighborhood Analysis (54.39.89.0/24)
Subnet Risk Profile: HIGH ABUSE
| Metric | Value |
|---|---|
| Subnet Classification | high_abuse |
| Total Siblings | 256 |
| Active Siblings | 178 |
| Threat Siblings | 194 |
| Abuse Density | 0.7578 (75.78%) |
| Inherited Risk Score | 30 |
| Neighbor Risk Distribution | 100 Medium / 0 High |
Key Finding: This /24 subnet demonstrates significant abuse activity with 194 threat-sibling IPs out of 178 active addresses. The neighborhood risk score of 30 suggests moderate-to-high contextual risk despite the target IP's moderate standalone score.
---
## Relationship Graph
The IP maintains 39 relationships, predominantly classified as "Same Network" entities tied to the OVH-CUST-281059691 network block. No direct associations to known malicious infrastructure or command-and-control networks were identified.
---
## Observation History
Total Historical Observations: 22 signals
Recent Activity Summary:
* 2026-06-28: Confirmed cloud infrastructure (OVH), no proxy/Tor/VPN characteristics. Operator score rated "Minimal" (0.1).
* 2026-06-20: Consistent OVH cloud infrastructure classification. BGP prefix 54.39.0.0/16 identified.
Temporal Indicators:
* Ownership Changes: 0
* Threat Persistence Days: 0
* Threat Observation Count: 1
* Persistently Malicious: No
The IP has exhibited stable cloud infrastructure characteristics with no escalation in threat indicators over the observation window.
---
## Recommended Security Actions
Risk Score: 50 / 100
Recommendation Level: Monitor / Block Based on Policy
Suggested Firewall Rules:
* iptables: `iptables -A INPUT -s 54.39.89.126 -j DROP`
* nftables: `nft add rule inet filter input ip saddr 54.39.89.126 drop`
* nginx: `deny 54.39.89.126;`
* pfSense: `54.39.89.126/32`
* Cloudflare WAF: Block IP with expression `ip.src eq 54.39.89.126`
* AWS WAF: Add address `54.39.89.126/32` to rule
Note: These recommendations are probabilistic and should be combined with other signals before taking action.
---
## Intelligence Assessment
IP 54.39.89.126 represents a cloud hosting address associated with Ahrefs infrastructure. The IP itself shows no active threat indicators but operates within a high-abuse neighborhood (75.78% abuse density). The geographic discrepancy and DNSBL listings warrant continued monitoring. While no direct malicious activity has been observed, the contextual risk from the subnet's abuse density suggests defensive blocking or rate-limiting policies may be appropriate for high-security environments.
Priority: MEDIUM
Status: Monitor / Evaluate for Blocking
Last Updated: Current observation cycle
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059691 |
| CIDR Block | 54.39.89.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca012-san126.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca012-san126.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 39% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 25% | 9 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-23 12:24:30 UTC |
| Last Seen | 2026-06-28 22:06:16 UTC |
| Profile Built | 2026-06-29 10:09:30 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 22 |
Full dossier details are available via our API.