## IP Intelligence Briefing: 51.161.37.149/32
Classification: Moderate Risk โ Cloud Infrastructure with High-Abuse Neighborhood
Summary
IP 51.161.37.149 resolves to OVH cloud infrastructure in Montreal, Canada (AS16276). The IP is associated with the domain ahrefs.net (proxy-ca005-san149.ahrefs.net) but presents no open services or active web endpoints. While the IP itself carries a moderate risk score of 40, it operates within a /24 subnet classified as high_abuse with an abuse density of 0.7188.
Infrastructure Profile
- Provider: OVH SAS (AS16276)
- Organization: Dmytro, Ahrefs Pte Ltd
- Network Block: 51.161.37.0/24
- Geolocation: Montreal, QC, CA
- Infrastructure Type: Cloud Compute / Hosting
- DNS Resolution: proxy-ca005-san149.ahrefs.net (forward confirmed: false)
- Service Status: No open ports detected โ endpoints are firewalled
Threat Indicators
- Risk Score: 40 (Moderate)
- Blacklist Status: 0 blacklists; 1 DNSBL listing (of 8 total lists)
- Threat Feeds: No known campaigns or threat indicators
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Operator Score: 0.2174 (Minimal)
- Geo Validation: RTT anomaly detected (observed 29ms vs. minimum possible 121.6ms for Montreal distance)
Neighborhood Analysis
The /24 subnet (51.161.37.0/24) exhibits elevated risk characteristics:
- Abuse Density: 0.7188 (High)
- Total Siblings: 256
- Active Siblings: 198
- Threat Siblings: 184
- Inherited Risk: 28
- Neighbor Risk Distribution: 99 medium-risk, 1 low-risk, 0 high-risk
The subnet demonstrates consistent risk patterns across sibling addresses (risk score 40, authority score 50), indicating systematic abuse or compromised infrastructure within this network block.
Observation History
Signal monitoring (20 observations) reveals:
- Recent threat detection on 2026-06-15 (confidence: 0.75)
- 4 threat pulses detected in recent observations
- Historical geolocation inconsistencies between sources
- Persistent cloud infrastructure classification
Recommendations
Standard blocking rules recommended across all platforms due to moderate risk profile and high-abuse neighborhood context:
- iptables: `iptables -A INPUT -s 51.161.37.149 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 51.161.37.149 drop`
- nginx: `deny 51.161.37.149;`
- pfSense: Block 51.161.37.149/32
- Cloudflare WAF: Block rule with expression `ip.src eq 51.161.37.149`
- AWS WAF: Block 51.161.37.149/32
Intelligence Notes
The IP appears to be part of OVH's customer infrastructure hosting ahrefs.net services. The high-abuse neighborhood classification suggests this subnet may be co-located with other compromised or abused endpoints. SOC teams should monitor for lateral activity from related IPs in the 51.161.37.0/24 block and consider broader subnet-level blocking if specific threat attribution is confirmed.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059684 |
| CIDR Block | 51.161.37.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca005-san149.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca005-san149.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 12% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 21:00:50 UTC |
| Last Seen | 2026-06-28 16:06:54 UTC |
| Profile Built | 2026-06-29 10:12:58 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.