THREAT INTELLIGENCE BRIEFING
Target: 51.222.95.208/32
Classification: Moderate Risk (Score: 40)
Date: 2026-06-22
EXECUTIVE SUMMARY
IP 51.222.95.208 is a cloud infrastructure endpoint hosted on OVH's infrastructure under Ahrefs Pte Ltd ownership. The IP is classified in a high-abuse subnet (51.222.95.0/24) with 73.8% abuse density and 189 threat-identified siblings. Current risk assessment indicates moderate threat level with no persistent malicious activity detected.
OWNERSHIP & INFRASTRUCTURE
- Provider: OVH (ASN 16276)
- Organization: Dmytro, Ahrefs Pte Ltd
- Netblock: 51.222.95.0/24 (OVH-CUST-281059689)
- Infrastructure Type: CloudCompute (OVH hosting)
- Registration: ARIN RIR
GEOLOCATION ANALYSIS
- Reported Location: Singapore
- Consensus: Inaccurate (Geo-validation violation detected)
- RTT Anomaly: 30ms measured vs. 112ms minimum possible for 5,598km distance
- Actual Data: Canadian origin inferred (CA/QC), 3,000km accuracy radius
- Geolocation Consensus: Multiple sources indicate non-plausible Singapore assignment
DNS & REVERSE LOOKUP
- PTR Record: proxy-ca010-san208.ahrefs.net
- Forward Resolution: proxy-ca010-san208.ahrefs.net (unconfirmed)
- Hosted Domain: ahrefs.net
- SSL/TLS: No certificates observed
- Service Status: No open ports detected (firewalled/no services)
THREAT INDICATORS
- Abuse Confidence: Not scored
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 total lists
- Malware Campaigns: None detected
NETWORK CONTEXT & NEIGHBORHOOD RISK
- Subnet Classification: High abuse density (0.7383)
- Total Subnet IPs: 256
- Active IPs: 234 (91.4% utilization)
- Threat-Associated Siblings: 189
- Inherited Risk Score: 29
- Network Reputation: Moderate risk across subnet
OBSERVATION HISTORY (20 signals)
Recent activity observed 2026-06-20 through 2026-06-22. Signals indicate:
- Stable operator score (0.2174, label: "Minimal")
- Consistent subnet abuse classification
- No escalation in threat signals
- Ownership stability (0 changes)
CONTROL PLANE DATA
- Route Stability: Unstable (false)
- Route Changes (30d): 0
- RPKI State: Not verified
- DNSSEC: Valid
- CAA Records: Present
- BGP Prefix: 51.222.0.0/16
RECOMMENDED ACTIONS
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 51.222.95.208 -j DROP
# nftables
nft add rule inet filter input ip saddr 51.222.95.208 drop
# nginx
deny 51.222.95.208;
# pfSense
51.222.95.208/32 (Block rule)
```
Cloud Platform Recommendations:
- Cloudflare WAF: Block expression: `ip.src eq 51.222.95.208`
- AWS WAF: Address: `51.222.95.208/32`
ANALYST NOTES
The IP resolves to an Ahrefs infrastructure hostname but lacks active services (no open ports, no web banner). High subnet abuse density warrants monitoring. Geographic inconsistencies suggest either misconfigured geo-database or potential spoofing. Recommend correlating with traffic logs before implementing permanent block; current risk score (40) supports blocking but does not indicate confirmed malicious activity.
CONFIDENCE LEVEL: Moderate
PERSISTENCE: Low (0 threat observation days)
RECOMMENDATION: Block with monitoring; re-evaluate if activity resumes
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059689 |
| CIDR Block | 51.222.95.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca010-san208.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca010-san208.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 23% | 1 | 2 |
| geolocation | 34% | 2 | 3 |
| Overall | 22% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-23 12:24:14 UTC |
| Last Seen | 2026-06-28 21:43:38 UTC |
| Profile Built | 2026-06-29 03:45:49 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.