IP INTELLIGENCE BRIEFING: 51.222.168.240/32
OVERVIEW
IP 51.222.168.240 carries a moderate risk score of 40 and is assigned to OVH SAS (ASN 16276) under organization Dmytro, Ahrefs Pte Ltd. The subnet 51.222.168.0/24 is classified as high abuse with an abuse density of 0.8086, containing 207 threat siblings among 222 active addresses.
OWNERSHIP & INFRASTRUCTURE
- ASN: 16276 (OVH SAS)
- CIDR Block: 51.222.168.0/24
- Infrastructure Type: CloudCompute (OVH hosting infrastructure)
- Network Role: Firewall/no services detected
- Classification: Not bogon, not proxy, not Tor
GEOLOCATION VIOLATIONS
Significant geolocation inconsistencies detected:
- Listed Location: Canada (CA), Quebec (QC)
- Reported City: Singapore
- Distance Discrepancy: 5,598 km with RTT of 27ms
- Minimum Possible RTT: 112ms for this distance
- Assessment: Geolocation data is implausible; indicates misconfiguration or spoofing
THREAT PROFILE
- Risk Score: 40 (Moderate Risk)
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0 direct blacklists
- DNSBL Listed: 1 of 8 total lists
- Abuse Confidence Score: Not available
DNS ANALYSIS
- PTR Hostname: proxy-ca018-san240.ahrefs.net
- Forward Resolution: proxy-ca018-san240.ahrefs.net
- Domain: ahrefs.net
- Forward Confirmation: False
- Email Auth: No SPF or DMARC records configured
NEIGHBORHOOD ANALYSIS
The 51.222.168.0/24 subnet exhibits elevated abuse characteristics:
- Abuse Density: 0.8086 (high)
- Risk Distribution: 100 medium-risk neighbors, 0 high-risk
- Total Siblings: 256
- Active Siblings: 222
- Threat Siblings: 207
- Inherited Risk Score: 32
OBSERVATION HISTORY
- 19 total observations recorded
- Most recent signals (2026-06-15): High abuse classification, OVH ASN attribution, operator score 0.2174 (minimal)
- Ownership stability: No ownership changes detected
- Threat persistence: 1 observation, not persistently malicious
RECOMMENDED ACTIONS
Firewall blocking rules recommended across multiple platforms:
- iptables: `iptables -A INPUT -s 51.222.168.240 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 51.222.168.240 drop`
- nginx: `deny 51.222.168.240;`
- pfSense: 51.222.168.240/32
- Cloudflare WAF: Block with expression `ip.src eq 51.222.168.240`
- AWS WAF: Add 51.222.168.240/32 to IPSet
ANALYST NOTES
The IP resides in a high-abuse OVH subnet with significant neighborhood risk. While the specific address shows no direct threat indicators, the geolocation violations and DNSBL listing warrant investigation. The PTR hostname suggests legitimate use (Ahrefs service), but the subnet abuse density indicates broader infrastructure risks. Consider blocking at perimeter firewalls and monitoring for associated activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059697 |
| CIDR Block | 51.222.168.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca018-san240.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca018-san240.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 03:10:15 UTC |
| Last Seen | 2026-06-28 17:50:07 UTC |
| Profile Built | 2026-06-29 05:52:59 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.