IPDebrief

51.161.37.33

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 51.161.37.33/32

Classification: Moderate Risk / High-Abuse Subnet

Date: Current

Analyst: IPDebrief Intelligence Team

---

## Executive Summary

IP 51.161.37.33 operates on OVH hosting infrastructure (ASN 16276) within Montreal, QC, Canada. The IP carries a risk score of 40 (Moderate Risk) and is part of subnet 51.161.37.0/24, which exhibits high abuse density (0.7422). No direct threat indicators were observed, but the neighborhood context requires elevated monitoring.

---

## Ownership & Infrastructure

AttributeValue
**ASN**16276 (OVH)
**Organization**Dmytro, Ahrefs Pte Ltd
**Network Name**OVH-CUST-281059684
**CIDR Block**51.161.37.0/24
**Geolocation**Montreal, QC, CA
**Infrastructure Type**Cloud Hosting
**Connection Type**Firewall / No Services

The IP resolves to PTR hostname `proxy-ca005-san33.ahrefs.net` with domain ahrefs.net. Forward DNS resolution is unconfirmed. Email authentication is absent (no SPF or DMARC records).

---

## Threat Assessment

Risk Score: 40 (Moderate)

Abuse Confidence: Not Available

Threat Indicators: None observed

No active threat campaigns or correlated IP indicators were identified. The IP does not exhibit persistent malicious behavior across the observation period.

---

## Neighborhood Context

Subnet: 51.161.37.0/24

Abuse Density: 0.7422 (High Abuse)

Classification: High Abuse

MetricValue
Total Siblings256
Active Siblings206
Threat Siblings190
Medium Risk Neighbors99
Low Risk Neighbors1

The subnet demonstrates elevated abuse activity with 190 threat-sibling IPs out of 206 active addresses. This indicates a high-abuse cloud environment typical of shared OVH hosting.

---

## Geolocation Validation

Status: โš ๏ธ DATA VIOLATION DETECTED

Geolocation data is implausible. The IP is not genuinely located in Canada based on RTT analysis. This may indicate routing anomalies or inaccurate geolocation databases.

---

## Observation History

Total Observations: 21

Recent observations (June 15-28, 2026) show:

The IP has maintained a stable risk profile with no evidence of escalating malicious activity.

---

## Network Classification

AttributeValue
ProviderOVH
Is CloudYes
Is CDNNo
Is VPNNo
Is ProxyNo
Is TorNo
Is HostingYes
Is MobileNo
Is ResidentialNo

---

## Recommended Actions

PlatformRule
**iptables**`iptables -A INPUT -s 51.161.37.33 -j DROP`
**nftables**`nft add rule inet filter input ip saddr 51.161.37.33 drop`
**nginx**`deny 51.161.37.33;`
**pfSense**`51.161.37.33/32`
**Cloudflare WAF**Block with expression: `ip.src eq 51.161.37.33`
**AWS WAF**Add IPSet: `51.161.37.33/32`

---

## Intelligence Assessment

This IP is hosted on OVH cloud infrastructure with moderate risk characteristics. While the IP itself lacks direct threat indicators, its placement in a high-abuse subnet (190/206 threat siblings) warrants defensive measures. The geolocation data should be treated as unreliable due to RTT violations.

Recommended SOC Response:

1. Implement blocking rules at perimeter firewalls

2. Monitor subnet 51.161.37.0/24 for correlated activity

3. Consider blocking entire /24 if operational constraints allow

4. Monitor for any changes in risk profile or new threat indicators

Confidence Level: Moderate โ€” Risk is elevated by neighborhood context despite clean individual IP profile.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡จ๐Ÿ‡ฆ Canada
RegionQC
CityMontreal
Timezoneโ€”
Latitude43.63
Longitude-79.37

๐Ÿข Ownership & Registration

OrganizationDmytro, Ahrefs Pte Ltd
ASNAS16276
Network NameOVH-CUST-281059684
CIDR Block51.161.37.0/24
RIRARIN
CountrySingapore
Abuse Contactโ€”

๐ŸŒ DNS Intelligence

PTRproxy-ca005-san33.ahrefs.net
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-ca005-san33.ahrefs.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
33%
23
routing
13%
11
services
15%
22
ownership
15%
22
reputation
22%
12
geolocation
33%
23
Overall22%1013
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Claimed geolocation contradicts RTT physics measurement

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-15 14:46:34 UTC
Last Seen2026-06-28 02:34:44 UTC
Profile Built2026-06-28 20:38:59 UTC
Data FreshnessLive
Signal Types20
Total Observations25
๐Ÿ” 20 signal types ยท 25 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.