IP Intelligence Briefing: 54.39.89.133
Date: June 15, 2026
---
**1. IP Profile**
- Risk Score: Moderate (40/100)
- Provider: OVH (AS16276)
- Organization: Ahrefs Pte Ltd (registered to "Dmytro")
- Geolocation: Quebec, Canada (Beauharnois; coordinates inferred)
- Network Role: Cloud Compute (OVH-hosted, no open services)
- DNS: Associated with `proxy-ca012-san133.ahrefs.net` (Ahrefs infrastructure)
---
**2. Threat Observations**
- Abuse Density: Subnet (54.39.89.0/24) classified as high_abuse (52.21% abuse density).
- Neighbor Risk: 88/100 neighbors flagged as medium-risk; 12 low-risk.
- Historical Signals:
- Listed in 1 DNSBL (confidence 0.35).
- Subnet abuse density observed (June 5, 2026).
- Network operator score: Minimal (0.2174).
---
**3. Relationships & Context**
- Network: Part of OVH-CUST-281059691 (249 IPs total, 97 active).
- DNS: Directly linked to Ahrefsβ `proxy-ca012-san133.ahrefs.net`.
- Threat Correlation: No direct malicious campaigns or threats detected.
---
**4. Neighborhood Analysis**
- Subnet Risk: High abuse density (52.21%) with 130 threat siblings.
- Neighbor Distribution:
- Medium Risk: 88 IPs (35.3%).
- Low Risk: 12 IPs (4.8%).
- Inherited Risk: 20% risk score from subnet context.
---
**5. Recommendations**
- Monitor: Track DNS activity and network traffic for anomalies, given the subnetβs high abuse density.
- Investigate: Verify if Ahrefsβ infrastructure is compromised or misconfigured.
- Segment: Consider isolating this subnet if internal traffic to/from it is suspicious.
- Threat Hunting: Cross-reference with Ahrefsβ known infrastructure to confirm legitimacy.
---
Conclusion:
The IP is part of a high-abuse subnet associated with Ahrefs, a legitimate SEO tool provider. While the IP itself shows no direct malicious activity, its network context and neighbor risk suggest potential exposure to broader threats. SOC teams should prioritize monitoring and investigate anomalies in this subnet.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059691 |
| CIDR Block | 54.39.89.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca012-san133.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca012-san133.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 21% | 1 | 2 |
| geolocation | 23% | 2 | 2 |
| Overall | 20% | 10 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-10 10:13:59 UTC |
| Last Seen | 2026-06-27 17:39:09 UTC |
| Profile Built | 2026-06-28 11:43:56 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 26 |
Full dossier details are available via our API.