# IP INTELLIGENCE BRIEFING: 54.39.89.226/32
Classification: Moderate Risk β Subnet Context Warning
Date: 2026-06-15
Analyst: IPDebrief Intelligence Team
## EXECUTIVE SUMMARY
IP 54.39.89.226 is a cloud hosting endpoint within OVH infrastructure associated with the ahrefs.net domain ecosystem. While the individual IP shows no direct malicious activity indicators, the /24 subnet (54.39.89.0/24) demonstrates elevated abuse characteristics with high abuse density (0.7539) and 193 flagged threat siblings out of 256 total addresses.
## NETWORK IDENTIFICATION
| Attribute | Value |
|---|---|
| **IP Address** | 54.39.89.226/32 |
| **ASN** | 16276 (OVH SAS) |
| **Organization** | Dmytro, Ahrefs Pte Ltd |
| **CIDR Block** | 54.39.89.0/24 |
| **Geolocation** | Beauharnois, Quebec, CA |
| **Infrastructure Type** | Cloud Compute / Hosting |
| **Provider** | OVH |
## THREAT ASSESSMENT
Individual IP Risk Score: 40/100 (Moderate Risk)
Direct Indicators
- Blacklist Status: 0 direct blacklist hits
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Known Campaigns: None identified
- Open Services: None detected (firewalled/no services)
- DNS Records: proxy-ca012-san226.ahrefs.net (ahrefs.net domain)
Subnet Context Risk
The parent /24 subnet exhibits concerning abuse patterns:
- Abuse Density: 0.7539 (HIGH)
- Threat Siblings: 193 of 256 IPs flagged as threats
- Active Siblings: 125 currently active
- Inherited Risk: 30/100
- Risk Distribution: All 100 sampled neighbors show consistent riskScore of 40
## OBSERVATION HISTORY
Analysis of 19 signal observations reveals:
- Recent DNS resolution to ahrefs.net infrastructure
- High abuse density classification confirmed in recent scans
- 8 total DNSBL listings with 1 active listing (maximum severity: high)
- Operator score: 0.2174 (Minimal threat operator classification)
- No evidence of persistent malicious behavior or sustained threat campaigns
## RELATIONSHIP GRAPH
37 relationships identified, primarily network-level associations:
- Multiple Same Network references to OVH-CUST-281059691
- No interconnection to known malicious campaigns or coordinated botnet infrastructure
## RECOMMENDED ACTIONS
Based on risk profile and subnet context, the following defensive measures are recommended:
Firewall Blocking:
```bash
# iptables
iptables -A INPUT -s 54.39.89.226 -j DROP
# nftables
nft add rule inet filter input ip saddr 54.39.89.226 drop
# Cloudflare WAF
{"description":"Block 54.39.89.226 β IPDebrief risk score 40","action":"block"}
```
Operational Guidance:
- Monitor for lateral movement within the 54.39.89.0/24 subnet
- Consider subnet-level blocking due to high abuse density
- Investigate any traffic patterns from the ahrefs.net reverse DNS hostname
- Evaluate context: ahrefs.net is a legitimate SEO tools provider; verify business justification for this endpoint
## CONCLUSION
IP 54.39.89.226 presents moderate risk primarily driven by subnet-level abuse patterns rather than direct malicious activity. The legitimate DNS association with ahrefs.net suggests potential legitimate hosting, but the high-density abuse environment warrants defensive blocking and ongoing monitoring. SOC analysts should correlate with local threat intelligence and consider the operational context before implementing blocking measures.
---
*Intelligence generated by IPDebriefβ’ β Defensive Security Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059691 |
| CIDR Block | 54.39.89.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca012-san226.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca012-san226.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 23% | 1 | 2 |
| geolocation | 26% | 2 | 2 |
| Overall | 21% | 10 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-24 00:33:23 UTC |
| Last Seen | 2026-06-28 23:33:41 UTC |
| Profile Built | 2026-06-29 05:35:58 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 22 |
Full dossier details are available via our API.