INTELLIGENCE BRIEFING: IP 51.222.95.163/32
Classification: Moderate Risk โ Network Abuse Indicator
Date: 2026-06-15
Analyst: IPDebrief Intelligence Team
---
EXECUTIVE SUMMARY
IP 51.222.95.163 is assigned to OVH (ASN 16276) under organization Ahrefs Pte Ltd. The IP carries a risk score of 40 (Moderate Risk) and is located within the 51.222.95.0/24 subnet, which exhibits high abuse density (0.75). While no active threat indicators or campaign affiliations were identified, the subnet's abuse profile warrants defensive monitoring.
---
OWNERSHIP & INFRASTRUCTURE
- Provider: OVH (CloudCompute hosting infrastructure)
- Organization: Dmytro, Ahrefs Pte Ltd
- Network Name: OVH-CUST-281059689
- ASN: 16276
- Routing: Origin AS16276, BGP prefix 51.222.0.0/16
- Infrastructure Type: Cloud hosting with firewalled configuration (no services exposed)
---
GEOLOCATION ANALYSIS
- Claimed Location: Singapore (QC region)
- Observed Location: Canada (QC)
- Geolocation Validity: INVALID
- Distance Discrepancy: 5,598 km between claimed and observed coordinates
- RTT Violation: Observed RTT 27.8ms vs minimum possible 112.0ms for claimed distance
- Assessment: Geographic data is unreliable; actual infrastructure location likely Canada based on RTT analysis
---
DNS & RESOLUTION
- PTR Hostname: proxy-ca010-san163.ahrefs.net
- Forward Resolution: proxy-ca010-san163.ahrefs.net (1 record)
- Status: Forward confirmation not validated
- Email Authentication: No SPF, DMARC, or TXT records detected
- Domain Association: ahrefs.net
---
THREAT INDICATORS
- Blacklist Count: 0
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Known Campaigns: None
- Threat Feeds: None populated
---
SUBNET NEIGHBORHOOD ASSESSMENT
- Subnet: 51.222.95.0/24
- Total Siblings: 256
- Active Siblings: 208
- Threat Siblings: 192
- Abuse Density: 0.75 (High Abuse)
- Inherited Risk: 30
- Classification: high_abuse
- Risk Distribution: 100 medium-risk IPs, 0 high/low-risk
The /24 subnet shows concentrated abuse activity with 75% abuse density. The IP inherits moderate risk from neighborhood context despite individual threat indicators being absent.
---
OBSERVATION HISTORY
- Total Observations: 19 signals
- Recent Activity: 2026-06-15 (subnet abuse classification)
- Threat Persistence: 0 days (no persistent malicious activity)
- Ownership Changes: 0 (stable ownership)
- Key Findings:
- Consistent subnet-level abuse classification observed
- Control plane operator score: 0.2174 (Minimal)
- No routing anomalies detected
- DNSSEC valid with CAA records present
---
NETWORK CLASSIFICATION FLAGS
- Provider: OVH
- Cloud: Yes
- Cdn: No
- Vpn: No
- Proxy: No
- Tor: No
- Hosting: Yes
- Mobile: No
- Residential: No
- Bogon: No
- Anycast: No
---
RECOMMENDED ACTIONS
Based on risk profile and neighborhood context, the following defensive measures are recommended:
Immediate Mitigation:
```bash
# iptables
iptables -A INPUT -s 51.222.95.163 -j DROP
# nftables
nft add rule inet filter input ip saddr 51.222.95.163 drop
# pfSense
51.222.95.163/32
```
Application-Level Blocking:
```nginx
# nginx
deny 51.222.95.163;
# Cloudflare WAF
{"description":"Block 51.222.95.163 โ IPDebrief risk score 40","action":"block","filter":{"expression":"ip.src eq 51.222.95.163"}}
# AWS WAF
{"Addresses":["51.222.95.163/32"],"Description":"IPDebrief risk 40"}
```
---
RISK ASSESSMENT
| Metric | Value | Severity |
|---|---|---|
| Overall Risk Score | 40 | Moderate |
| Provider Score | 0 | N/A |
| Authority Score | 0 | N/A |
| Subnet Abuse Density | 0.75 | High |
| Threat Indicators | 0 | None |
| Campaign Affiliation | None | None |
---
CONCLUSION
IP 51.222.95.163 represents a moderate-risk address within a high-abuse OVH hosting subnet. While the individual IP lacks direct threat indicators, the subnet's 75% abuse density and 192 threat siblings suggest elevated risk of abuse or exploitation activity. The unreliable geolocation data and lack of exposed services indicate the IP may be part of a cloud infrastructure with limited public-facing exposure.
Recommendation: Monitor for activity from the 51.222.95.0/24 subnet. Consider implementing subnet-level filtering if false positive risk is acceptable. No immediate threat action required, but defensive blocking rules recommended pending operational context.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059689 |
| CIDR Block | 51.222.95.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca010-san163.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca010-san163.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 25% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 21:00:56 UTC |
| Last Seen | 2026-06-28 16:24:33 UTC |
| Profile Built | 2026-06-29 04:28:14 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.