## IP Intelligence Briefing: 51.222.168.22/32
Classification: Moderate Risk (Score: 40) | Status: Active Cloud Infrastructure
Ownership & Infrastructure:
IP 51.222.168.22 is hosted on OVH Infrastructure (ASN: 16276) under customer "OVH-CUST-281059697," registered to Dmytro, Ahrefs Pte Ltd. The IP operates within the 51.222.168.0/24 CIDR block and is classified as cloud computing infrastructure with hosting capabilities. DNS resolution returns proxy-ca018-san22.ahrefs.net, indicating association with the ahrefs.net domain ecosystem.
Geolocation Discrepancy:
Geolocation data indicates Canada (QC) with city reported as Singapore, creating a 5,598km distance discrepancy. RTT measurements (27-32ms) contradict the claimed geographic origin, as the minimum possible RTT for this distance would be 112ms. This indicates false geolocation data or routing anomalies requiring verification.
Threat Assessment:
The IP carries a moderate risk score of 40 with no direct threat indicators. No open ports are detected, and the system shows as "Firewalled / No Services." The IP is not listed as known attacker, spam source, or Tor exit. However, DNSBL listing exists (1 of 8 total blacklists), and operator risk score is 0.2174.
Neighborhood Analysis:
The /24 subnet (51.222.168.0/24) demonstrates elevated risk characteristics:
- Abuse density: 0.7812 (high_abuse classification)
- 200 of 229 active siblings flagged as threats
- Inherited risk score: 31
- Neighbor risk distribution: 99 medium, 1 low
Observation History:
Twenty-four signals recorded between June 18-19, 2026. Recent observations show consistent operator scores (0.2174) and subnet abuse density at 0.7812. No persistent malicious behavior detected (threat persistence: 0 days).
Relationship Graph:
Fifty-six relationships identified, predominantly network associations with OVH-CUST-281059697. The relationship topology indicates integration within the broader OVH infrastructure ecosystem.
Recommended Actions:
- Monitor inbound connections to this subnet given high abuse density
- Verify geolocation claims during incident response
- Consider blocking at perimeter if traffic is unexplained
- Correlate with ahrefs.net domain activity for context
Summary: This IP operates as cloud hosting infrastructure within a high-abuse density subnet. While the specific address shows no active threat indicators, the neighborhood context warrants defensive monitoring. The geolocation discrepancy should be flagged during forensic analysis.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059697 |
| CIDR Block | 51.222.168.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca018-san22.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca018-san22.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:26 UTC |
| Last Seen | 2026-06-27 06:54:47 UTC |
| Profile Built | 2026-06-28 01:00:29 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.