# IP Intelligence Briefing: 54.39.89.180
## Executive Summary
IP 54.39.89.180 is classified as Moderate Risk (Risk Score: 40) with no active threat indicators. The IP is assigned to OVH Cloud infrastructure in Beauharnois, Quebec, Canada, under customer organization "Dmytro, Ahrefs Pte Ltd" (AS16276). While the IP itself shows no malicious activity, the /24 subnet exhibits high abuse density (0.7539) with 193 identified threat siblings out of 125 active neighbors.
## Technical Profile
- ASN/Provider: AS16276 (OVH), Customer: OVH-CUST-281059691
- Geolocation: Beauharnois, QC, CA (3000km accuracy radius)
- Network Role: CloudCompute / Hosting (Firewalled / No Services)
- DNS Resolution: proxy-ca012-san180.ahrefs.net (ahrefs.net domain)
- Infrastructure Type: Cloud hosting (not CDN, VPN, proxy, or Tor)
- Service Status: No open ports detected; firewall-protected
## Threat Assessment
- Risk Score: 40 (Moderate)
- Abuse Confidence: Not applicable (no active threat indicators)
- Blacklist Count: 0
- Threat Feeds: None matched
- Campaign Correlation: 0 correlated IPs
- Known Campaigns: None
Key Observations:
- No active threat indicators detected in current profile
- IP is not listed on threat feeds (Pulsedive, etc.)
- Not associated with Tor, spam sources, or known attacker campaigns
- No persistent malicious activity observed over time
- 23 historical observations show consistent benign classification
## Neighborhood Analysis
Subnet 54.39.89.0/24 presents elevated neighborhood risk:
- Abuse Density: 0.7539 (High)
- Active Siblings: 125/256 (49% utilization)
- Threat Siblings: 193 identified
- Risk Distribution: 100 medium-risk neighbors, 0 high-risk neighbors
Context: The subnet hosts multiple OVH customers with similar risk profiles. The high abuse density suggests shared infrastructure risk typical of cloud hosting environments.
## Historical Signals
Analysis of 23 observations (most recent: 2026-06-20T14:40:17Z):
- Geolocation signals consistently place IP in Canada (CA)
- Network classification stable as OVH hosting
- Subnet abuse density classification: high_abuse (consistent)
- No ownership changes detected
- No threat persistence patterns observed
## Recommended Actions
No immediate blocking required based on current threat profile. Consider the following:
1. Monitor: Track for new threat indicators (blacklist additions, campaign correlations)
2. Contextualize: Evaluate traffic patterns against organizational threat intelligence
3. Subnet Awareness: Be aware of elevated risk in parent /24 subnet (193 threat siblings)
4. Geographic Context: Geographic discrepancy detected (5628km from probe location with minimum RTT 29ms; flagged as RTT violation)
## Intelligence Notes
- IP is associated with ahrefs.net domain (legitimate SEO analytics company)
- Hostname pattern (proxy-ca012-san180) suggests proxy/relay service configuration
- Cloud hosting environment with firewall protection
- No evidence of direct malicious activity despite neighborhood abuse density
- Recommend treating as low-priority monitoring target unless traffic patterns indicate otherwise
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059691 |
| CIDR Block | 54.39.89.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca012-san180.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca012-san180.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 20% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 26% | 3 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 26% | 12 | 18 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 21:01:09 UTC |
| Last Seen | 2026-06-28 16:48:50 UTC |
| Profile Built | 2026-06-29 04:53:19 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 27 |
Full dossier details are available via our API.