INTELLIGENCE BRIEFING: 51.222.95.158/32
Executive Summary
IP address 51.222.95.158 resolved to hostname proxy-ca010-san158.ahrefs.net under ASN 16276 (OVH). The endpoint carries a moderate risk score of 40 with no active threat indicators. However, geolocation validation failed, subnet abuse density remains high at 0.7266, and 186 of 256 siblings in the /24 block were classified as threats.
Ownership and Network Classification
The IP belongs to OVH-CUST-281059689 within the 51.222.95.0/24 CIDR block. Organization registration shows Dmytro, Ahrefs Pte Ltd. Network role classification indicates hosting infrastructure with no open ports or services detected. The endpoint is associated with the ahrefs.net domain, resolving to proxy-ca010-san158.ahrefs.net. DNSSEC validation passed; RPKI state and IRR consistency remain unverified.
Geolocation Anomalies
Geolocation data reported Canada (QC) with claimed Singapore coordinates at 3,000 km accuracy radius. RTT measurements (27-33ms) violated physical distance constraintsβminimum expected RTT for 5,598 km distance was 112ms. This discrepancy indicates either spoofed geolocation data or significant routing anomalies.
Threat Indicators and Reputation
Abuse confidence score returned null. Blacklist enumeration showed 0 matches across threat feeds. DNSBL listing recorded 1 of 8 total lists. No Tor exit node activity detected. Known attacker flags, spam source indicators, and campaign affiliations all registered negative.
Subnet Neighborhood Analysis
The 51.222.95.0/24 subnet demonstrated high abuse classification with abuse density of 0.7266. Of 256 total sibling addresses, 232 remained active with 186 threat siblings. Inherited risk score of 29 reflects subnet-level contamination. Neighbor risk scores uniformly rated at 40 with authority scores of 50.
Observation History
Historical tracking captured 23 signal observations. The most recent observation (2026-06-18) confirmed subnet abuse density at 0.7266. Ownership changes registered at zero with no persistent malicious threat patterns identified.
Recommended Actions
No specific firewall rules or security actions generated by automated analysis. The IP presents moderate risk primarily through geolocation inconsistencies and subnet-level abuse density rather than direct threat indicators.
Assessment
The endpoint exhibits characteristics of compromised or misconfigured infrastructure within a hosting environment. While no direct attack indicators were observed, the high abuse density of the parent subnet and geolocation validation failures warrant monitoring. No immediate blocking recommended; implement enhanced monitoring for this IP and adjacent subnet addresses.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059689 |
| CIDR Block | 51.222.95.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca010-san158.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca010-san158.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:26 UTC |
| Last Seen | 2026-06-27 07:03:49 UTC |
| Profile Built | 2026-06-28 01:10:50 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.