IP Intelligence Briefing: 54.39.89.26
Date: 2026-06-01
---
**1. Core Profile**
- Risk Score: 25 (Low Risk)
- Ownership: Owned by Dmytro, Ahrefs Pte Ltd (OVH ASN 16276).
- Geolocation: Canada (QC, Beauharnois).
- Network Role: CloudCompute infrastructure (OVH-hosted, no residential/mobile traits).
- Threat Indicators: No malicious activity detected (no blacklists, spam, or known attacker associations).
---
**2. Network Behavior**
- Subnet: 54.39.89.0/24
- Subnet Abuse Density: 43.21% (moderate risk, mixed benign/malicious activity).
- Neighbors:
- 54 IPs in subnet (54 active, 105 flagged as threats).
- 10 high-risk neighbors (medium/low scores).
- Control Plane:
- BGP prefix: 54.39.0.0/16.
- DNSSEC valid, CAA records present.
- No route stability issues.
---
**3. Relationships & DNS**
- DNS Associations:
- Resolves to proxy-ca012-san26.ahrefs.net (ahrefs.net domain).
- No SPF/DKIM records detected.
- Network Links:
- Same subnet as 243 IPs (OVH-CUST-281059691).
- No direct ties to malicious organizations or campaigns.
---
**4. Historical Observations**
- Threat Observations: 1 total (no persistent threats).
- Geolocation Consensus: Plausible (CA, Quebec).
- Activity Trends: No significant changes in risk scores or DNS behavior.
---
**5. Recommendations**
- Monitor Subnet: The 54.39.89.0/24 subnet has moderate abuse density; investigate anomalous activity in neighboring IPs.
- Verify DNS: Ensure ahrefs.netโs DNS configurations (CAA, SPF) are secure, as no email authentication records were detected.
- Baseline Behavior: No immediate action required for 54.39.89.26, but track subnet activity for potential lateral movement.
Conclusion: This IP appears to be a legitimate cloud server owned by Ahrefs, with no direct malicious indicators. However, its subnet shows mixed risk, warranting closer monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059691 |
| CIDR Block | 54.39.89.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca012-san26.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca012-san26.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 21% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-20 17:48:47 UTC |
| Last Seen | 2026-06-28 12:28:20 UTC |
| Profile Built | 2026-06-29 06:34:20 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.