# IP Intelligence Briefing: 54.39.89.42/32
## Executive Summary
IP address 54.39.89.42 presents a Moderate Risk profile (Risk Score: 40) operating within OVH cloud infrastructure. The IP is associated with Ahrefs Pte Ltd but exhibits geographic inconsistencies and operates within a high-abuse-density subnet. No active threat indicators are present, but the network neighborhood context warrants defensive monitoring.
## Profile Overview
- Risk Score: 40 (Moderate Risk)
- ASN: 16276 (OVH)
- Organization: Dmytro, Ahrefs Pte Ltd
- Network: OVH-CUST-281059691
- Geolocation: Beauharnois, QC, Canada (CA)
- Infrastructure Type: Cloud Compute / Hosting
- Registration Date: Not available
## Network Context & Neighborhood Analysis
The IP operates within subnet 54.39.89.0/24, which exhibits elevated abuse characteristics:
- Abuse Density: 0.7578 (High)
- Classification: high_abuse
- Active Siblings: 178 of 256 total
- Threat Siblings: 194 IPs flagged as threats
- Inherited Risk Score: 30
All 100 sampled neighboring IPs show medium-risk classification, indicating systemic risk within this allocation.
## Threat Indicators
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 lists checked
- Open Services: None detected (Firewalled/No Services)
- Threat Feeds: No indicators
## Geolocation Anomalies
RTT analysis reveals a geographic inconsistency:
- Reported Distance: 5,629 km from probe location
- Measured RTT: 27.0 ms
- Minimum Possible RTT: 112.6 ms
- Status: VIOLATION โ RTT is less than minimum possible for reported distance
This discrepancy may indicate IP spoofing, misconfigured geolocation data, or use of a proxy/anycast layer.
## DNS & Network Services
- PTR Hostname: proxy-ca012-san42.ahrefs.net
- Associated Domain: ahrefs.net
- Forward Resolution: Confirmed
- Open Ports: None detected
- TLS Certificates: None
- Email Authentication: SPF/DMARC not configured
## Historical Observations
Analysis covers 21 observations spanning recent monitoring periods:
- Subnet Abuse Classification: High abuse density noted (June 20, 2026)
- Geolocation Updates: Consistent Canada reporting
- Threat Persistence: 0 days (not persistently malicious)
- Ownership Changes: 0 occurrences
## Recommended Actions
Based on risk profile and neighborhood context, the following controls are recommended:
Firewall Rules
- iptables: `iptables -A INPUT -s 54.39.89.42 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 54.39.89.42 drop`
- nginx: `deny 54.39.89.42;`
- pfSense: 54.39.89.42/32
WAF Rules
- Cloudflare WAF: Block IP 54.39.89.42 (Risk Score: 40)
- AWS WAF: Add 54.39.89.42/32 to blocklist
Monitoring Recommendations
1. Monitor subnet 54.39.89.0/24 for coordinated activity
2. Track geographic discrepancies across related IPs
3. Review firewall rules effectiveness after implementation
4. Correlate with Ahrefs domain activity for context
## Risk Assessment
The IP represents moderate risk primarily due to:
1. High-abuse-density neighborhood context
2. Geographic reporting anomalies
3. Hosting infrastructure classification
4. Lack of service exposure (reduces immediate exploitation risk)
No active malicious indicators detected. Recommended blocking until further investigation clarifies IP purpose and activity patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059691 |
| CIDR Block | 54.39.89.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca012-san42.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca012-san42.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 38% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 26% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 03:10:38 UTC |
| Last Seen | 2026-06-28 18:06:54 UTC |
| Profile Built | 2026-06-29 06:09:07 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 25 |
Full dossier details are available via our API.