# IP Intelligence Briefing: 54.39.89.177/32
Classification: Moderate Risk | Risk Score: 40 | Status: Active Observation
## Executive Summary
IP address 54.39.89.177 resolves to infrastructure hosted on OVH cloud network (ASN 16276) associated with organization Ahrefs Pte Ltd. The IP exhibits moderate risk characteristics with geolocation data showing validation discrepancies. Subnet-level analysis indicates elevated abuse density with 148 active threat siblings in the /24 range.
## Infrastructure Profile
- Network Classification: OVH cloud computing infrastructure with hosting designation
- Ownership: OVH-CUST-281059691, ASN 16276
- Registered Organization: Ahrefs Pte Ltd (RIR: ARIN)
- Geolocation: Beauharnois, QC, Canada (CA)
- Service Status: Firewalled/No services detected; no open ports on common ranges
- DNS Resolution: proxy-ca012-san177.ahrefs.net (ahrefs.net)
## Threat Indicators
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Known Campaigns: None identified
- Blacklist Status: 0 traditional blacklists; 1 DNSBL listing detected
- Operator Score: 0.2174 (Minimal operator risk)
## Network Context & Subnet Analysis
The /24 subnet 54.39.89.0/24 demonstrates high abuse classification with the following metrics:
- Abuse Density: 0.5781 (high)
- Inherited Risk Score: 23
- Total Sibling IPs: 256
- Active Sibling IPs: 182
- Threat Sibling IPs: 148
- Neighborhood Risk Distribution: 100 medium risk neighbors; 0 high risk
## Geolocation Validation
Geolocation data indicates validation anomalies. While geolocation sources report Canada (Beauharnois, QC), RTT-based validation reveals a significant discrepancy:
- Reported Distance: 5,628.6 km
- Minimum Possible RTT: 112.6 ms
- Observed RTT: 26.0 ms
- Violation: Observed RTT below minimum possible for reported distance
This suggests either geolocation spoofing, misattribution, or infrastructure located in an unreported region.
## Historical Observations
Eighteen signal observations recorded in observation history. Recent activity includes:
- Subnet abuse density classification (0.5781)
- DNS resolution for ahrefs.net with CAA records present
- Operator score assessment indicating minimal threat
## Recommended Actions
Based on risk profile, the following security measures are recommended:
Firewall Rules:
- iptables: `iptables -A INPUT -s 54.39.89.177 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 54.39.89.177 drop`
- nginx: `deny 54.39.89.177;`
WAF Rules:
- Cloudflare WAF: Block IP 54.39.89.177 (Risk Score: 40)
- AWS WAF: Add 54.39.89.177/32 to block list
Classification: This IP warrants defensive blocking at perimeter firewalls and WAF layers due to subnet-level abuse density and geolocation inconsistencies. Consider monitoring for lateral connections to other IPs within the 54.39.89.0/24 subnet.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059691 |
| CIDR Block | 54.39.89.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca012-san177.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca012-san177.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 15% | 2 | 2 |
| reputation | 27% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 21% | 9 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-11 08:59:13 UTC |
| Last Seen | 2026-06-27 19:25:49 UTC |
| Profile Built | 2026-06-28 13:32:34 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 23 |
Full dossier details are available via our API.