# IP Intelligence Briefing: 54.39.89.173/32
## Executive Summary
IP address 54.39.89.173 is a moderate-risk (40/100) hosting infrastructure endpoint operated by OVH (ASN 16276) under the organization "Dmytro, Ahrefs Pte Ltd." The subnet demonstrates elevated abuse density (0.7578) with 194 of 256 total siblings classified as threat sources. No active threat indicators were detected, though geolocation validation anomalies and DNSBL listings warrant monitoring.
## Infrastructure Profile
- Owner/Operator: OVH (ASN 16276), Customer ID: OVH-CUST-281059691
- Organization: Dmytro, Ahrefs Pte Ltd
- Geolocation: Beauharnois, QC, CA (3000km accuracy radius)
- Network Classification: Hosting provider, firewalled/no services detected
- DNS Resolution: proxy-ca012-san173.ahrefs.net (forward resolution unconfirmed)
- Email Authentication: SPF/DMARC not configured
## Risk Assessment
| Metric | Value |
|---|---|
| Risk Score | 40 (Moderate Risk) |
| Abuse Confidence | Null |
| DNSBL Listings | 1 of 8 total lists |
| Operator Score | 0.2174 (Minimal) |
| Threat Persistence | 0 days |
| Campaign Likelihood | None |
## Neighborhood Analysis
The 54.39.89.0/24 subnet exhibits high-abuse classification with the following distribution:
- Abuse Density: 0.7578 (high)
- Threat Siblings: 194 of 256 total IPs
- Active Siblings: 167 of 256
- Neighbor Risk Profile: Uniform risk score of 40 across sampled neighbors
## Threat Indicators
- Known Attacker: No
- Tor Exit Node: No
- Proxy/VPN: No
- Spam Source: No
- Active Campaigns: None detected
- Threat Feeds: Empty
## Geolocation Validation
Anomaly Detected: RTT measurement (28.0ms) is inconsistent with reported geolocation distance (5629km). Minimum possible RTT for this distance should be 112.6ms. This discrepancy suggests either inaccurate geolocation data or routing anomalies.
## Historical Observations
21 observations recorded as of 2026-06-20. Recent signals indicate:
- Consistent Canada (CA) country code attribution
- Stable abuse density metrics (0.7578)
- Minimal operator classification
- No ownership changes detected
## Related Entities
52 relationships identified, primarily network-level associations (OVH-CUST-281059691). No certificate, hostname, or organization-level correlations beyond network classification.
## Recommended Actions
- Monitor: Track for escalation in risk score or new threat indicators
- Block: No immediate blocking recommended; risk score below typical threshold
- Investigate: Geolocation validation anomaly warrants further review if this IP appears in suspicious traffic patterns
- Whitelist Consideration: Legitimate hosting infrastructure with no active threat indicators
## Intelligence Summary
This IP represents OVH hosting infrastructure with moderate risk characteristics driven primarily by subnet-level abuse density rather than individual IP threat activity. The high-abuse subnet classification suggests this endpoint may be shared infrastructure commonly used for legitimate hosting alongside potentially compromised neighbors. No direct threat intelligence indicators detected; monitoring recommended for contextually relevant traffic patterns.
*Report generated: 2026-06-20*
*Data sources: IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059691 |
| CIDR Block | 54.39.89.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca012-san173.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca012-san173.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 14:58:07 UTC |
| Last Seen | 2026-06-28 14:50:23 UTC |
| Profile Built | 2026-06-29 08:56:23 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.