# IP Threat Intelligence Briefing
Target: 51.222.168.164/32
Date: Current analysis period
Classification: Moderate Risk / High Abuse Neighborhood
---
## Executive Summary
IP 51.222.168.164 is an OVH cloud hosting address associated with Ahrefs Pte Ltd. The IP presents a moderate risk profile (risk score: 40) but operates within a subnet exhibiting exceptionally high abuse density (0.8047). While the IP itself shows no direct threat indicators, the neighborhood context warrants defensive monitoring.
---
## Network Ownership & Infrastructure
- ASN: 16276 (OVH SAS)
- Organization: Dmytro, Ahrefs Pte Ltd
- CIDR Block: 51.222.168.0/24
- Infrastructure Type: Cloud Compute (OVH hosting)
- Network Classification: Cloud infrastructure with hosted domain proxy-ca018-san164.ahrefs.net
---
## Risk Assessment
| Metric | Value | Assessment |
|---|---|---|
| Overall Risk Score | 40 | Moderate Risk |
| Abuse Confidence | Not applicable | No direct abuse indicators |
| DNSBL Listings | 1 of 8 | Minimal reputation impact |
| Control Plane Stability | False | Route changes detected |
| Threat Persistence | 0 days | No persistent malicious activity |
---
## Neighborhood Analysis (51.222.168.0/24)
The subnet exhibits concerning abuse characteristics:
- Abuse Density: 0.8047 (HIGH)
- Subnet Classification: high_abuse
- Active Siblings: 229 of 256 IPs
- Threat Siblings: 206 (80.3% of active IPs)
- Risk Distribution: 100 medium-risk neighbors, 0 high-risk neighbors
Implication: This subnet is heavily utilized for potentially abusive activities. The IP's moderate risk score may be mitigated by firewall configuration, but neighborhood risk inheritance score is 32.
---
## Technical Observations
- DNS Records: Single PTR hostname (proxy-ca018-san164.ahrefs.net)
- Forward Resolution: Unconfirmed (forwardConfirmed: false)
- Services: No open ports detected (firewalled/no services)
- TLS/HTTP: No TLS certificates or HTTP headers exposed
- Geolocation: Reported as CA (Canada) but geolocation validation flags implausibility (RTT 35ms vs minimum 112ms for 5,598km distance)
---
## Historical Signals (21 observations)
- Consistent classification as OVH cloud hosting
- Persistent Ahrefs domain association
- Sustained high-abuse subnet classification
- No emergence of new threat indicators
---
## Recommended Actions
1. Monitoring Priority: Medium - Monitor for outbound connections from this subnet
2. Firewall Rules: Block or rate-limit traffic from 51.222.168.0/24 if policy requires
3. Investigation Focus: Verify legitimacy of traffic; neighborhood abuse density suggests potential compromised hosts
4. Blocklist Consideration: Add subnet 51.222.168.0/24 to blocklist if blocking individual IPs is operationally impractical
---
## SOC Notes
This IP represents a legitimate hosting provider (Ahrefs) operating in a high-abuse subnet. The discrepancy between individual IP risk and neighborhood risk suggests either: (a) IP has effective local security controls, or (b) risk scoring varies by individual IP within the subnet. Recommend correlation with actual traffic patterns and threat intelligence feeds for definitive classification.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059697 |
| CIDR Block | 51.222.168.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca018-san164.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca018-san164.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 03:10:14 UTC |
| Last Seen | 2026-06-28 17:49:27 UTC |
| Profile Built | 2026-06-29 05:52:59 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.