# IP Intelligence Briefing: 51.161.65.192/32
## Executive Summary
IP 51.161.65.192 is a cloud compute infrastructure endpoint operated by OVH under organization Dmytro, Ahrefs Pte Ltd (ASN 16276). The IP resolves to proxy-ca011-san192.ahrefs.net and is geolocated to Montreal, Quebec, Canada. Risk assessment indicates moderate threat (score: 40) with no active threat indicators, though the subnet exhibits elevated abuse density (0.7109).
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 40 (Moderate Risk) |
| **ASN** | 16276 (OVH) |
| **Organization** | Dmytro, Ahrefs Pte Ltd |
| **Network** | OVH-CUST-281059690 (51.161.65.0/24) |
| **Location** | Montreal, QC, CA |
| **Infrastructure Type** | Cloud Compute / Hosting |
| **Services** | None detected (Firewalled) |
## Threat Intelligence
- Threat Indicators: None detected
- Blacklist Status: Listed on 1 of 8 DNSBLs
- Known Attacker: No
- Spam Source: No
- Tor/Proxy: No
- Campaign Activity: None correlated
## Neighborhood Analysis
The /24 subnet (51.161.65.0/24) demonstrates elevated abuse characteristics:
- Abuse Density: 0.7109 (High)
- Active Siblings: 209 of 256
- Threat Siblings: 182
- Subnet Classification: high_abuse
All sampled neighbors report risk score 40, indicating consistent moderate-risk posture across the subnet.
## Observation History
Signal history reveals consistent network classification with periodic DNS resolution activity:
- Latest Resolution: ahrefs.net (2026-06-28)
- Operator Score: 0.2174 (Minimal)
- Geolocation Validity: RTT anomalies detected (25ms observed vs. 121.6ms minimum for 6082km distance)
- Threat Persistence: None observed
## Intelligence Narrative
This IP is part of Ahrefs' cloud infrastructure hosting environment. The moderate risk rating derives primarily from subnet-level abuse density rather than individual IP threat activity. The geolocation discrepancy (RTT violation) warrants monitoring but does not indicate spoofing, as this is common in cloud hosting environments with anycast routing. The IP maintains clean threat indicators and no known malicious associations.
## Recommended Actions
- Allow with Monitoring: Legitimate hosting endpoint; no immediate blocking required
- Subnet Awareness: Monitor 51.161.65.0/24 for elevated abuse activity
- Baseline Comparison: Use as reference point for Ahrefs infrastructure traffic patterns
- DNS Verification: Confirm resolution to ahrefs.net domain for expected traffic
## Classification
Status: Operational Infrastructure
Threat Level: Moderate (Contextual - Subnet)
Action: Monitor / Allow with logging
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059690 |
| CIDR Block | 51.161.65.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca011-san192.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca011-san192.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 23% | 1 | 2 |
| geolocation | 40% | 2 | 3 |
| Overall | 23% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-24 00:32:56 UTC |
| Last Seen | 2026-06-28 23:27:06 UTC |
| Profile Built | 2026-06-29 05:28:02 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.