# INTELLIGENCE BRIEFING: IP 54.39.89.193/32
Classification: MODERATE RISK
Risk Score: 40/100
Report Generated: 2026-06-21
## EXECUTIVE SUMMARY
IP address 54.39.89.193 is a cloud-hosted infrastructure endpoint associated with OVH (ASN 16276). The IP resolves to ahostname affiliated with ahrefs.net but operates within a subnet exhibiting high abuse density (77.34%). No active services or open ports detected. Recommended action: Block at perimeter firewall.
---
## OWNERSHIP & GEOLOCATION
- Organization: Dmytro, Ahrefs Pte Ltd
- Netname: OVH-CUST-281059691
- ASN: 16276 (OVH)
- Location: Beauharnois, Quebec, Canada (CA)
- CIDR Block: 54.39.89.0/24
- Infrastructure Type: Cloud Compute / Hosting
---
## NETWORK CLASSIFICATION
| Attribute | Value |
|---|---|
| Is Cloud | Yes |
| Is CDN | No |
| Is Hosting | Yes |
| Is Proxy | No |
| Is Tor Exit | No |
| Is Residential | No |
| Is Bogon | No |
| Service Purpose | Firewalled / No Services |
---
## DNS ANALYSIS
- PTR Hostname: proxy-ca012-san193.ahrefs.net
- Domain: ahrefs.net
- Forward Resolution: Not confirmed
- Email Authentication:
- SPF: Not configured
- DMARC: Not configured
- TXT Records: 0
---
## THREAT INDICATORS
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Campaign Matches: 0
- DNSBL Listings: 1 of 8 total lists
---
## NEIGHBORHOOD ANALYSIS (54.39.89.0/24)
| Metric | Value |
|---|---|
| Abuse Density | 0.7734 (HIGH) |
| Classification | High Abuse |
| Total Siblings | 256 |
| Active Siblings | 130 |
| Threat Siblings | 198 |
| Inherited Risk | 30/100 |
The subnet demonstrates elevated abuse activity with 77.34% abuse density. 198 of 256 sibling IPs are classified as threat sources.
---
## OBSERVATION HISTORY
Recent signal observations indicate:
- Consistent DNS resolution to ahrefs.net domain
- Subnet abuse density classified as "high_abuse"
- Operator score: 0.2174 (Minimal)
- Route stability: False
- No persistent malicious behavior observed
---
## SECURITY RECOMMENDATIONS
Based on risk score (40) and neighborhood context, the following firewall rules are recommended:
iptables
```bash
iptables -A INPUT -s 54.39.89.193 -j DROP
```
nftables
```bash
nft add rule inet filter input ip saddr 54.39.89.193 drop
```
Cloudflare WAF
```json
{
"description": "Block 54.39.89.193 โ IPDebrief risk score 40",
"action": "block",
"filter": {
"expression": "ip.src eq 54.39.89.193"
}
}
```
AWS WAF
```json
{
"Addresses": ["54.39.89.193/32"],
"Description": "IPDebrief risk 40"
}
```
---
## ASSESSMENT
This IP represents moderate-risk cloud hosting infrastructure within a high-abuse subnet. While the IP itself shows no active threat indicators, the neighborhood context (77% abuse density, 198 threat siblings) suggests elevated risk. The hostname association with ahrefs.net appears legitimate, but DNS forward resolution is unconfirmed and email authentication records are missing. Recommend blocking at network perimeter and monitoring for any behavioral changes.
Status: BLOCK RECOMMENDED
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059691 |
| CIDR Block | 54.39.89.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca012-san193.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca012-san193.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 21% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 17% | 1 | 2 |
| geolocation | 19% | 2 | 2 |
| Overall | 17% | 9 | 10 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-03 18:32:08 UTC |
| Last Seen | 2026-06-21 10:52:42 UTC |
| Profile Built | 2026-06-21 11:21:21 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.