IP Intelligence Briefing: 51.161.65.100
Date: 2026-06-09
**Overview**
- Risk Score: 25 (Low Risk)
- Provider: OVH (ASN 16276)
- Ownership: Dmytro, Ahrefs Pte Ltd (OVH-CUST-281059690)
- Geolocation: Singapore (CA), inferred from DNS records.
- Network Role: CloudCompute infrastructure (hosting provider).
---
**Threat Indicators**
- No malicious activity detected: No indicators of compromise (IoCs), spam, or known attacker activity.
- Services: Scanned for open ports (no active services detected).
- DNS: Linked to `proxy-ca011-san100.ahrefs.net` (Ahrefs DNS hostname).
---
**Observation History**
- Recent Signals (June 2026):
- Minimal operational risk (operator score: 0.2174).
- No DNS anomalies or routing issues.
- Subnet (`51.161.65.0/24`) shows mixed classification with 30.77% abuse density.
- No persistent threats or ownership changes.
---
**Network Relationships**
- Connected Entities:
- OVH network (`OVH-CUST-281059690`).
- Ahrefs DNS (`proxy-ca011-san100.ahrefs.net`).
- Subnet Neighbors:
- 247 total IPs in `51.161.65.0/24`.
- 76 IPs flagged as potentially abusive (30.77% abuse density).
- 120 active IPs, 12 with inherited risk.
---
**Actionable Insights**
1. Monitor Subnet: The subnet has a moderate abuse density; monitor for unusual activity.
2. Verify DNS Associations: Confirm `proxy-ca011-san100.ahrefs.net` is legitimate (Ahrefs is a known hosting provider).
3. No Firewall Actions Needed: No immediate mitigation required due to low risk profile.
---
**Conclusion**
This IP is part of a legitimate cloud hosting infrastructure (OVH/Ahrefs) with no signs of malicious activity. However, its subnet exhibits mixed risk, warranting continued monitoring for potential lateral movements or abuse. No immediate defensive action is required, but ensure alignment with broader network segmentation policies.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059690 |
| CIDR Block | 51.161.65.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca011-san100.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca011-san100.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 21:00:50 UTC |
| Last Seen | 2026-06-28 16:09:55 UTC |
| Profile Built | 2026-06-29 10:15:17 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.