IP Intelligence Briefing: 51.161.65.235
Date: 2026-06-06
---
**1. Core Profile**
- Risk Score: Moderate (40/100)
- Provider: OVH (AS16276)
- Organization: Dmytro, Ahrefs Pte Ltd (OVH-CUST-281059690)
- Geolocation: Montreal, QC, Canada (geo validation flagged as implausible due to RTT anomalies).
- Network Role: CloudCompute (OVH-hosted server, no residential/mobile traffic).
- DNS: Resolves to `proxy-ca011-san235.ahrefs.net` (Ahrefs, legitimate).
---
**2. Threat & Abuse Indicators**
- Threat Signals: No direct malicious indicators (no malware, phishing, or C2 activity).
- DNSBL Listing: Appears on 1/8 DNSBLs (low risk).
- Subnet Abuse:
- 51.161.65.0/24 has high_abuse classification (abuse density 51%).
- 127/249 siblings in subnet show threat activity.
- 167 active IPs in subnet, with 93 medium-risk and 7 low-risk neighbors.
---
**3. Historical Observations**
- Recent Activity:
- Last 30 days: 21 observations (moderate risk).
- Geo validation issues: RTT of 26ms for 6,082km distance (implausible).
- Network stability: Route changes detected (unstable routing).
---
**4. Relationships & Network Context**
- Linked Entities:
- Subnet: `51.161.65.0/24` (OVH-CUST-281059690).
- DNS: Ahrefs (`ahrefs.net`).
- No direct ties to known malicious campaigns or organizations.
---
**5. Recommendations**
1. Monitor Subnet: The `/24` subnet has high abuse density; investigate neighboring IPs for potential lateral movement.
2. Verify Geolocation: The IPβs low RTT for Montreal, Canada, may indicate spoofing or proxy activity.
3. Check DNSBL Status: Confirm why this IP is listed on 1/8 DNSBLs; investigate potential false positives or minor abuse.
4. Network Segmentation: Ensure cloud compute instances are isolated to prevent internal exposure.
---
Conclusion:
This IP is associated with a legitimate cloud provider (OVH) and appears to host a server for Ahrefs. While no direct threats are detected, the subnetβs high abuse density and geo validation anomalies warrant further investigation. SOC teams should monitor for unusual traffic patterns or changes in subnet behavior.
*Generated by IPDebrief | © 2026 Jason Alberino*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059690 |
| CIDR Block | 51.161.65.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca011-san235.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca011-san235.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 15% | 2 | 2 |
| reputation | 27% | 1 | 3 |
| geolocation | 37% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-11 02:51:41 UTC |
| Last Seen | 2026-06-27 18:54:44 UTC |
| Profile Built | 2026-06-28 13:01:10 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 27 |
Full dossier details are available via our API.