# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 51.161.65.139/32
Classification: Moderate Risk (Score: 40/100)
Report Date: Current
Analyst: Automated Intelligence System
---
## EXECUTIVE SUMMARY
IP 51.161.65.139 is a hosting infrastructure address owned by OVH SAS (ASN 16276) operating under the Ahrefs Pte Ltd organizational entity. The IP is hosted in Montreal, Quebec, Canada and resolves to ahrefs.net. Despite corporate domain association, the IP exhibits moderate risk characteristics with blacklist presence and operates within a high-abuse density subnet.
---
## NETWORK IDENTIFICATION
| Attribute | Value |
|---|---|
| **ASN** | 16276 (OVH) |
| **Organization** | Dmytro, Ahrefs Pte Ltd |
| **Netname** | OVH-CUST-281059690 |
| **CIDR Block** | 51.161.65.0/24 |
| **Geolocation** | Montreal, QC, Canada |
| **Infrastructure Type** | Cloud Computing (Hosting) |
---
## THREAT ASSESSMENT
Risk Profile: Moderate Risk (Score: 40/100)
Threat Indicators:
- Blacklist Count: 1 (of 8 total DNSBL checks)
- Abuse Confidence Score: Not applicable
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- VPN/Proxy: No
Control Plane Data:
- Origin ASN: 16276
- BGP Prefix: 51.161.0.0/17
- Route Stability: False
- DNSSEC Valid: True
- DNSBL Listed: 1/8 lists
---
## SUBNET ANALYSIS (51.161.65.0/24)
Abuse Density: 0.6094 (High Abuse Classification)
Subnet Statistics:
- Total Siblings: 256 IPs
- Active Siblings: 207
- Threat Siblings: 156
- Risk Distribution: 100 medium, 0 high, 0 low
Risk Context: The /24 subnet exhibits elevated abuse density with 156 identified threat siblings. This contextualizes the moderate risk score within a higher-risk network environment.
---
## DNS & SERVICE ANALYSIS
| Component | Status |
|---|---|
| **PTR Hostname** | proxy-ca011-san139.ahrefs.net |
| **Forward Hostname** | proxy-ca011-san139.ahrefs.net |
| **Forward Confirmed** | False |
| **Domain** | ahrefs.net |
| **Open Ports** | None detected |
| **TLS Certificate** | Not detected |
| **HTTP Services** | None detected |
Note: Services show as "Firewalled / No Services" โ IP may be configured for non-public access or uses load balancing.
---
## OBSERVATION HISTORY
Recent signals indicate consistent infrastructure characteristics:
- June 28, 2026: Listed on 1 blacklist (max severity: high)
- June 20, 2026: Geolocation confirmed (Canada), cloud hosting classification
- Stability: Ownership stable with zero changes recorded
---
## RECOMMENDED ACTIONS
Blocking Recommendations:
- iptables: `iptables -A INPUT -s 51.161.65.139 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 51.161.65.139 drop`
- nginx: `deny 51.161.65.139;`
- pfSense: Block 51.161.65.139/32
- Cloudflare WAF: Block rule with expression `ip.src eq 51.161.65.139`
- AWS WAF: Add 51.161.65.139/32 to blocklist
Operational Notes:
- Consider subnet-level monitoring due to high abuse density (0.6094)
- Blacklist presence suggests potential reputation concerns
- No active threat campaigns correlated
---
## ANALYST RECOMMENDATION
Monitor this IP for 72 hours with traffic logging. The moderate risk score combined with high-abuse subnet context warrants observation, but immediate blocking may impact legitimate ahrefs.net operations. Implement rate limiting or allowlisting if business requirements for ahrefs.net services exist.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059690 |
| CIDR Block | 51.161.65.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca011-san139.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca011-san139.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 20% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 14:57:54 UTC |
| Last Seen | 2026-06-28 14:15:03 UTC |
| Profile Built | 2026-06-29 02:20:21 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 21 |
Full dossier details are available via our API.