## IP Intelligence Briefing: 51.222.168.94/32
Executive Summary: This IP address is hosted on OVH cloud infrastructure (ASN 16276) under organization Dmytro, Ahrefs Pte Ltd. The address presents moderate risk (score: 40) with associated subnet 51.222.168.0/24 classified as high-abuse density. The IP is not currently flagged as a known attacker or spam source, but the hosting environment warrants monitoring due to elevated neighborhood threat metrics.
Infrastructure Profile:
- Provider: OVH (CloudCompute)
- Ownership: Dmytro, Ahrefs Pte Ltd
- Netblock: 51.222.168.0/24
- Infrastructure Type: Cloud hosting with firewall enabled
- Network Role: Cloud compute infrastructure with no actively open services detected
- Control Plane: BGP prefix 51.222.0.0/16, route stable, RPKI state unknown
DNS Analysis:
- PTR Hostname: proxy-ca018-san94.ahrefs.net
- Domain: ahrefs.net
- Forward Resolution: Confirmed (1 hostname)
- Email Authentication: No SPF or DMARC records configured
- DNSBL Status: Listed on 1 of 8 total DNSBL lists
Threat Indicators:
- Risk Score: 40 (Moderate)
- Abuse Confidence Score: Not reported
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Correlation: None identified
- Blacklist Count: 0 direct threat indicators
Network Neighborhood Analysis:
- Subnet Classification: High abuse (51.222.168.0/24)
- Abuse Density: 0.6211 (Elevated)
- Inherited Risk Score: 24
- Total Sibling IPs: 256
- Active Sibling IPs: 231
- Threat Sibling IPs: 159 (62% of active siblings flagged as threats)
- Risk Distribution: 100 medium-risk neighbors, 0 high-risk neighbors
Geolocation Validation:
- Claimed Location: Singapore (QC region)
- Inferred Location: Canada (Quebec)
- Validation Status: FAILED
- Observed RTT: 29ms
- Minimum Possible RTT: 112ms (for 5,598km distance)
- Assessment: RTT violation indicates geolocation spoofing or data inconsistency
Observation History (29 total signals):
- Recent observations from 2026-06-25 through 2026-06-27
- Subnet abuse density consistently reported at 0.6211
- Multiple operator score signals (0.2174 - "Minimal" operator impact)
- No persistent malicious behavior pattern detected
- Single threat observation recorded
Relationship Graph:
- 70 total relationships identified
- Primary association: Same network (OVH-CUST-281059697)
- Multiple network-level connections to OVH infrastructure
Recommended Security Actions:
1. Monitor, Block: Consider firewall rules blocking inbound connections due to high-abuse neighborhood density
2. Enhanced Logging: Log all outbound traffic to this IP for 30 days
3. DNS Analysis: Investigate ahrefs.net domain associations for legitimacy
4. Subnet Watch: Monitor adjacent /24 subnet 51.222.168.0/24 for correlated malicious activity
Conclusion: The IP address 51.222.168.94 is not currently acting as a direct threat vector. However, the high-abuse density of its hosting subnet and geolocation validation failure suggest the infrastructure may be leveraged by bad actors. Monitor for activity patterns and maintain defensive posture against lateral movement from the associated subnet.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059697 |
| CIDR Block | 51.222.168.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca018-san94.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca018-san94.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 4 |
| routing | 24% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 27% | 3 | 4 |
| reputation | 31% | 1 | 3 |
| geolocation | 37% | 2 | 3 |
| Overall | 28% | 12 | 19 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-09 17:41:40 UTC |
| Last Seen | 2026-06-27 16:24:38 UTC |
| Profile Built | 2026-06-28 16:30:24 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 32 |
Full dossier details are available via our API.