# IP Intelligence Briefing: 51.161.65.246/32
Classification: Moderate Risk (Score: 40) | Jurisdiction: Canada | Infrastructure: OVH CloudCompute
## Executive Summary
IP 51.161.65.246 is a cloud infrastructure endpoint assigned to OVH-CUST-281059690 (ASN 16276) under organization Dmytro, Ahrefs Pte Ltd. Located in Montreal, QC, the address is associated with Ahrefs.net domain infrastructure. Current risk assessment indicates moderate threat posture with elevated neighborhood-level abuse signals.
## Threat Profile
- Risk Score: 40/100 (Moderate)
- Provider: OVH (CloudCompute/Hosting infrastructure)
- Service Status: Firewalled / No Services Detected
- DNS Record: proxy-ca011-san246.ahrefs.net
- Geolocation: Montreal, QC, Canada (43.6319°N, -79.3716°W)
- Network Classification: Cloud infrastructure with hosting designation
## Abuse Indicators
- DNSBL Listed: 1 of 8 total blacklists
- Blacklist Count: 0
- Operator Score: 0.2174 (Minimal)
- Route Stability: Unstable (route changes detected)
- Known Threats: No Tor exit, no known attacker indicators, no spam source classification
## Neighborhood Analysis
Subnet 51.161.65.0/24 exhibits elevated abuse characteristics:
- Abuse Density: 0.75 (High abuse classification)
- Total Siblings: 256 addresses
- Active Siblings: 213 (83% active rate)
- Threat Siblings: 192 (75% of active addresses flagged)
- Inherited Risk Score: 30/100
## Observation History
26 observations recorded, most recent on 2026-06-29. Key temporal signals include:
- High abuse density classification (0.75) consistently observed
- Subnet-level threat correlation present
- Geolocation signals confirm Canadian origin
## Relationship Graph
38 relationships identified, primarily same-network associations to OVH-CUST-281059690. No external entity correlations detected.
## Recommended Actions
Based on risk profile and neighborhood context, the following firewall rules are recommended:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 51.161.65.246 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 51.161.65.246 drop` |
| nginx | `deny 51.161.65.246;` |
| pfSense | Block CIDR: 51.161.65.246/32 |
| Cloudflare WAF | Expression: `ip.src eq 51.161.65.246` โ Block |
| AWS WAF | CIDR Block: 51.161.65.246/32 |
## Assessment
The IP is a legitimate cloud infrastructure address associated with Ahrefs (SEO tools provider). However, the high-abuse-density neighborhood (192 threat siblings) and route instability suggest potential for abuse by bad actors leveraging the hosting infrastructure. Monitor for any changes in service signatures or threat indicators. No immediate evidence of malicious activity against this specific endpoint, but defensive blocking is warranted due to neighborhood context.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059690 |
| CIDR Block | 51.161.65.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca011-san246.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Hosted Domain | ip246.ip-51-161-65.net |
| Forward Hostnames | proxy-ca011-san246.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 32% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 22% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-25 00:41:37 UTC |
| Last Seen | 2026-06-29 01:03:01 UTC |
| Profile Built | 2026-06-29 07:04:26 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 25 |
Full dossier details are available via our API.