IP Intelligence Briefing: 54.39.89.184
*Generated via IPDebrief tools for SOC analysis*
---
**1. Core Profile**
- Risk Score: 25 (Low Risk)
- Ownership: Registered to Ahrefs Pte Ltd (OVH, ASN 16276)
- Geolocation:
- Country: US (New York)
- Subnet: 54.39.89.0/24
- Confirmed as cloud-hosted infrastructure (OVH CloudCompute)
- Threat Indicators: No malicious activity detected. No known attacker, spam, or Tor associations.
- Network Role:
- Cloud-based server (OVH)
- No public services (open ports, TLS certs, or HTTP banners)
---
**2. Observation History**
- Latest Risk Signal (June 12, 2026):
- Risk Score: 66 (Proxy/VPN association)
- Source: ProxyCheck.io (Canada, Quebec)
- Classification: "Minimal" risk with mixed geolocation anomalies.
- Trend: Stable over 30 days; no persistent malicious activity.
---
**3. Relationships**
- DNS Associations:
- Linked to proxy-ca012-san184.ahrefs.net (Ahrefs infrastructure).
- Network:
- Subnet 54.39.89.0/24 (OVH-CUST-281059691)
- Shared ownership with 246 IPs in the subnet.
---
**4. Neighborhood Analysis**
- Subnet Abuse Density:
- 86/100 IPs classified as medium-risk (likely cloud/VPN infrastructure).
- 14/100 IPs low-risk (legitimate services).
- Neighboring IPs:
- 114 IPs flagged as potential threats (e.g., proxies, misconfigured hosts).
- 83 active IPs in the subnet.
---
**5. Key Findings & Recommendations**
- Low Risk but Contextual Concerns:
- The IP is part of Ahrefs' infrastructure, but its association with a proxy service (via DNS) raises questions about potential misuse.
- Subnet has moderate abuse density, suggesting monitoring for lateral movement or compromised hosts.
- Actionable Steps:
1. Monitor subnet traffic for anomalies (e.g., unexpected DNS queries, TLS handshake failures).
2. Verify proxy service legitimacy (Ahrefs is a legitimate company, but ensure no unauthorized use).
3. Check for DNS misconfigurations in the 54.39.89.0/24 subnet.
---
Conclusion: 54.39.89.184 is a low-risk cloud server with no direct malicious indicators. However, its subnet contains a mix of legitimate and potentially risky hosts, requiring ongoing monitoring. No immediate mitigation actions are required unless proxy activity escalates.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059691 |
| CIDR Block | 54.39.89.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca012-san184.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca012-san184.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 22% | 1 | 3 |
| geolocation | 24% | 2 | 3 |
| Overall | 20% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-30 06:23:16 UTC |
| Last Seen | 2026-06-29 07:24:44 UTC |
| Profile Built | 2026-06-29 07:33:23 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 25 |
Full dossier details are available via our API.