## IP INTELLIGENCE BRIEFING: 51.222.168.36/32
Classification: MODERATE RISK | Last Updated: 2026-06-20
---
EXECUTIVE SUMMARY
IP 51.222.168.36 is a moderate-risk (score: 40) OVH hosting infrastructure endpoint associated with Ahrefs Pte Ltd. While the IP itself shows no direct threat indicators, it operates within a high-abuse subnet (51.222.168.0/24) with a 72.27% abuse density rating, requiring elevated monitoring.
---
OWNERSHIP & NETWORK CLASSIFICATION
- ASN: 16276 (OVH)
- Organization: Dmytro, Ahrefs Pte Ltd
- CIDR Block: 51.222.168.0/24
- Network Name: OVH-CUST-281059697
- Infrastructure Type: CloudCompute (OVH)
- RIR: ARIN
---
GEOLOCATION ANALYSIS
- Primary Location: Singapore (latitude/longitude: null)
- Secondary Location: Canada (QC)
- Accuracy Radius: 3,000 km
- GeoConsensus: Active (2 sources)
- Note: Geographic data inconsistency detected (Singapore vs Canada) โ common in CDN/cloud hosting environments
---
THREAT INDICATORS
- Blacklist Count: 0
- Abuse Confidence: Not scored
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Known Campaigns: None
- Threat Feeds: None
- DNSBL Listed: 1 of 8 total lists
---
DNS & SERVICE PROFILE
- PTR Hostnames: proxy-ca018-san36.ahrefs.net
- Reverse DNS: Confirmed (1 forward resolution)
- Open Ports: None detected
- HTTP Services: None detected
- TLS Certificates: None
- Email Auth (SPF/DMARC): Not configured
---
SUBNET NEIGHBORHOOD ANALYSIS
- Subnet: 51.222.168.0/24
- Abuse Density: 0.7227 (HIGH)
- Classification: HIGH_ABUSE
- Total Siblings: 256
- Active Siblings: 222 (86.7%)
- Threat Siblings: 185 (74.3%)
- Inherited Risk Score: 28
Key Finding: The subnet exhibits elevated abuse activity with 74.3% of active IPs flagged as threats. This contextual risk elevates the monitoring priority for this endpoint.
---
OBSERVATION HISTORY
- Total Observations: 23 signals
- Latest Observation: 2026-06-20T12:16:09 UTC
- Historical Provider: OVH (consistent)
- Abuse Density Trend: Stable at 0.7227 across observation period
- Threat Persistence: 0 days
- Is Persistently Malicious: No
---
RELATIONSHIP GRAPH
- Total Relationships: 45
- Primary Association: OVH-CUST-281059697 (Same Network)
- Related Entities: 40+ network-level relationships
---
SECURITY ACTIONS & RECOMMENDATIONS
No specific blocking actions recommended for this IP based on current risk profile. However, the following monitoring advisories apply:
1. Elevated Monitoring: Due to high-abuse subnet classification (72.27% abuse density), implement enhanced logging and alerting for this endpoint.
2. Traffic Pattern Analysis: Monitor for deviations from normal Ahrefs proxy traffic patterns.
3. Geolocation Consistency: Investigate Singapore vs Canada geolocation discrepancy for potential spoofing indicators.
4. Subnet-Wide Assessment: Consider evaluating adjacent IPs in 51.222.168.0/24 for correlated malicious activity.
---
CONCLUSION
IP 51.222.168.36 is a legitimate OVH hosting endpoint for Ahrefs services with no direct threat indicators. However, its placement within a high-abuse subnet (51.222.168.0/24) necessitates continued monitoring. The IP should be allowed with enhanced logging, but security teams should remain vigilant for anomalous traffic patterns that may indicate compromise or abuse of the hosting infrastructure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059697 |
| CIDR Block | 51.222.168.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca018-san36.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca018-san36.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 21% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 14:57:58 UTC |
| Last Seen | 2026-06-28 14:24:08 UTC |
| Profile Built | 2026-06-29 08:29:27 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 26 |
Full dossier details are available via our API.