## IP INTELLIGENCE BRIEFING: 51.222.95.161/32
Classification: Moderate Risk | Risk Score: 40/100 | Subnet Classification: High Abuse
EXECUTIVE SUMMARY
IP 51.222.95.161 belongs to OVH cloud infrastructure under organization Dmytro, Ahrefs Pte Ltd (ASN 16276). The IP is classified within a high-abuse subnet (51.222.95.0/24) with 71.88% abuse density. Despite legitimate ownership association with Ahrefs, the neighborhood analysis indicates elevated risk requiring defensive monitoring.
OWNERSHIP & INFRASTRUCTURE
- Provider: OVH (Cloud Hosting)
- Network Block: 51.222.95.0/24
- Infrastructure Type: CloudCompute / Hosting
- DNS Resolution: proxy-ca010-san161.ahrefs.net (ahrefs.net domain)
- Control Plane: BGP prefix 51.222.0.0/16, route stability: unstable
- Services: No open ports detected; endpoint appears firewalled
GEOLOCATION DATA
- Reported Country: CA (Canada)
- Coordinates: 56.13°N, -106.35°W (plausibility: 35%)
- Confidence: Low โ geolocation validation shows geographic implausibility
- Note: Hostname suggests Singapore deployment; significant discrepancy between reported and inferred location
THREAT INDICATORS
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0
- Abuse Confidence Score: Not assigned
- Threat Persistence: Not persistently malicious
- Campaign Correlation: None detected
NEIGHBORHOOD ANALYSIS
The /24 subnet (51.222.95.0/24) exhibits concerning metrics:
- Abuse Density: 0.7188 (71.88%)
- Total Siblings: 256
- Active Siblings: 234
- Threat Siblings: 184
- Inherited Risk: 28
- Risk Distribution: 100 medium-risk, 0 high/low risk neighbors
- Classification: High abuse environment
OBSERVATION HISTORY
Recent signal history (last 20 observations) shows:
- Consistent high-abuse classification since June 2026
- Stable provider/ownership signals
- No significant risk escalation or de-escalation trends
- Recent operator score: 0.2174 (Minimal threat classification)
RECOMMENDED ACTIONS
IMMEDIATE DEFENSIVE MEASURES:
1. Firewall Blocking: Recommended for inbound traffic
- `iptables -A INPUT -s 51.222.95.161 -j DROP`
- `nft add rule inet filter input ip saddr 51.222.95.161 drop`
2. WAF Rules:
- Cloudflare: Block with expression `ip.src eq 51.222.95.161`
- AWS WAF: Add to blocklist with description "IPDebrief risk 40"
RISK MITIGATION NOTES:
- While ownership traces to Ahrefs (legitimate SEO infrastructure), the high-abuse neighborhood warrants blocking
- No direct threat indicators present, but subnet-level risk is significant
- Monitor for outbound C2 traffic or data exfiltration attempts from this IP
- Consider blocking entire /24 subnet if traffic patterns confirm malicious activity
INTELLIGENCE CONTEXT
This IP represents a moderate-risk endpoint within a compromised or heavily abused hosting block. The discrepancy between legitimate ownership and high neighborhood abuse density suggests either:
- Compromised infrastructure
- Legitimate services operating in an abused block
- Shared hosting abuse affecting multiple tenants
Recommendation: Apply block rules while monitoring for traffic patterns that might indicate legitimate use versus malicious activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059689 |
| CIDR Block | 51.222.95.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca010-san161.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca010-san161.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 43% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-20 11:46:59 UTC |
| Last Seen | 2026-06-28 11:59:08 UTC |
| Profile Built | 2026-06-29 06:03:22 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.