IP Intelligence Briefing: 51.222.168.226
Date: 2026-06-09
---
**1. Core Profile**
- Risk Score: 40 (Moderate Risk)
- Ownership: Owned by Dmytro, Ahrefs Pte Ltd (OVH ASN 16276).
- Geolocation: Registered to Canada (CA), but geolocation data shows conflicting "Singapore" city label (likely misattribution).
- Network Role: CloudCompute instance (OVH infrastructure).
- Threat Indicators: No known malicious activity, spam, or campaign associations.
---
**2. Observation History**
- Recent Activity: No significant changes in risk scores or threat signals over the past 30 days.
- Geolocation Anomalies: RTT (Round-Trip Time) of 27ms suggests proximity to Singapore, conflicting with registered Canadian location.
---
**3. Relationships & Network Context**
- Subnet: 51.222.168.0/24 (OVH-CUST-281059697).
- Neighbor Risk:
- High Risk: 0 IPs
- Medium Risk: 96 IPs
- Low Risk: 4 IPs
- Subnet Abuse Density: 57.87% (classified as "high_abuse").
- Shared Network: 254 IPs in the subnet, with 147 flagged as threats.
---
**4. Security Recommendations**
- Firewall Rules:
- iptables: `iptables -A INPUT -s 51.222.168.226 -j DROP`
- Cloudflare WAF: Block IP with rule `ip.src eq 51.222.168.226`.
- AWS WAF: Add `51.222.168.226/32` to a new rule.
- Action Notes: No immediate blocking required, but monitor for anomalies due to subnet abuse density.
---
**5. Summary**
The IP 51.222.168.226 is a legitimate cloud instance owned by Ahrefs, part of a subnet with high abuse density. While no direct malicious activity is observed, the subnetβs risk profile and geolocation inconsistencies warrant closer monitoring. SOC teams should investigate unusual traffic patterns and consider mitigating the subnet if further threats emerge.
Next Steps:
- Validate geolocation data with additional probes.
- Monitor subnet activity for escalations in risk.
- Apply firewall rules to isolate the IP if it becomes suspicious.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059697 |
| CIDR Block | 51.222.168.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca018-san226.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca018-san226.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-21 21:00:55 UTC |
| Last Seen | 2026-06-28 16:22:22 UTC |
| Profile Built | 2026-06-29 04:25:56 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.