# IP Intelligence Briefing: 51.222.95.153/32
## Executive Summary
IP address 51.222.95.153 is a cloud hosting infrastructure endpoint associated with OVH datacenter operations. The IP presents a moderate risk profile (score: 40) with no confirmed malicious indicators. However, the subnet exhibits high abuse density, warranting defensive monitoring.
## Technical Profile
Ownership & Registration:
- ASN: 16276 (OVH)
- Organization: Dmytro, Ahrefs Pte Ltd
- Network: OVH-CUST-281059689
- CIDR Block: 51.222.95.0/24
Geolocation:
- Reported Location: Canada (QC/Singapore)
- Geolocation Validation: Plausibility flags indicate data inconsistency (RTT 27ms vs minimum 112ms for reported distance)
- Network: Cloud infrastructure with hosting characteristics
DNS Resolution:
- PTR Hostname: proxy-ca010-san153.ahrefs.net
- Resolved Domain: ahrefs.net
- Forward Confirmation: Pending validation
## Threat Assessment
Current Risk Status: Moderate Risk (Score: 40)
- Blacklist Count: 0
- Known Campaigns: None identified
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Infrastructure Classification:
- Type: CloudCompute / Hosting
- Service Status: Firewalled / No Services Detected
- Open Ports: None
## Neighborhood Analysis
Subnet: 51.222.95.0/24
- Abuse Density: 0.6875 (High)
- Classification: High Abuse
- Active Siblings: 202 of 256
- Threat Siblings: 176
- Risk Distribution: 100 medium-risk neighbors (0 high, 0 low)
The subnet demonstrates consistent moderate-risk characteristics across all sampled addresses, with a significant concentration of threat-associated peers.
## Observation History
19 observations recorded as of 2026-06-14:
- Cloud infrastructure characteristics consistently identified
- DNS resolution for ahrefs.net confirmed
- Geolocation signals show Canadian attribution
- No escalation in threat signals over observation period
## Relationship Network
55 relationships identified, primarily:
- Same Network: OVH-CUST-281059689 (50+ instances)
- Network-level associations indicate OVH hosting infrastructure
## Control Plane Data
- BGP Prefix: 51.222.0.0/16
- Route Stability: False
- DNSSEC Valid: Yes
- DNSBL Listed: 1 of 8 lists
## Recommended Actions
Firewall Recommendations:
- DROP traffic from 51.222.95.153/32
- Consider subnet-level blocking (51.222.95.0/24) given high abuse density
Platform-Specific Rules:
- iptables: `iptables -A INPUT -s 51.222.95.153 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 51.222.95.153 drop`
- nginx: `deny 51.222.95.153;`
- pfSense: Block 51.222.95.153/32
- Cloudflare WAF: Block IP (risk score 40)
- AWS WAF: Add to blocklist (51.222.95.153/32)
## Intelligence Narrative
The IP 51.222.95.153 operates as a firewalled cloud hosting endpoint within the OVH provider infrastructure. While no direct threat indicators have been observed, the parent subnet (51.222.95.0/24) demonstrates elevated abuse characteristics with 68.75% abuse density. The IP resolves to ahostname associated with Ahrefs.net, suggesting legitimate web infrastructure usage. However, the combination of cloud hosting infrastructure, high neighborhood abuse density, and geolocation inconsistencies warrants defensive blocking. SOC teams should monitor for any service activation on this endpoint and consider broader subnet-level restrictions given the consistent moderate-risk profile across all 256 addresses in the /24 block.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059689 |
| CIDR Block | 51.222.95.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca010-san153.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca010-san153.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 21% | 9 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-08 11:10:41 UTC |
| Last Seen | 2026-06-27 13:20:30 UTC |
| Profile Built | 2026-06-28 07:25:57 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 27 |
Full dossier details are available via our API.