IP Intelligence Briefing: 51.222.95.21
Date: 2026-06-18
---
**1. Profile Summary**
- Risk Score: 40 (Moderate Risk)
- Ownership: Owned by OVH-CUST-281059689 (Dmytro, Ahrefs Pte Ltd).
- Geolocation:
- Country: Canada (CA)
- Region: Quebec (QC)
- City: Singapore (inconsistent with regional data; potential spoofing or misconfiguration).
- Network Role: CloudCompute infrastructure (OVH-hosted, no open services).
- Threat Indicators: No direct malicious activity detected (no abuse confidence, no blacklists, no campaigns).
- DNS:
- PTR hostname: `proxy-ca010-san21.ahrefs.net` (linked to Ahrefs, a legitimate SEO company).
- No email auth records (SPF, DMARC).
---
**2. Observation History**
- Recent Activity (2026-06-14 to 2026-06-18):
- High Abuse Density: Subnet `51.222.95.21/24` has 0.6875 abuse density, with 176 threat siblings (176 IPs in the subnet flagged as malicious).
- Signal Consistency: Mixed results (minimal risk scores, but some DNS and routing anomalies).
- Geolocation Discrepancy: IP reported as "Singapore" but geolocated to Canada (QC).
---
**3. Relationships**
- Network Affiliation:
- Part of OVH-CUST-281059689 (ASN 16276).
- Subnet `51.222.95.0/24` linked to high_abuse classification.
- Linked Entities:
- Ahrefs Pte Ltd (parent organization).
- No direct ties to known malicious campaigns or domains.
---
**4. Neighborhood Analysis**
- Subnet: `51.222.95.21/24` (256 IPs total).
- Risk Distribution:
- High Risk: 0 IPs
- Medium Risk: 85 IPs
- Low Risk: 15 IPs
- Threat Siblings: 176 IPs in subnet flagged as malicious.
- Abuse Density: 68.75% of subnet IPs are associated with abuse or malicious activity.
---
**5. Actionable Intelligence**
- SOC Recommendation:
- Monitor Subnet: The `51.222.95.0/24` subnet has a high abuse density. Investigate if this IP is part of a larger malicious infrastructure.
- Verify Geolocation: Discrepancy between reported "Singapore" and Canada (QC) may indicate spoofing or misconfigured DNS.
- Check Ahrefs Compliance: Confirm if Ahrefs Pte Ltd has policies to mitigate abuse in their OVH-hosted infrastructure.
- Block Subnet (if justified): If further threats are detected in the subnet, consider blocking traffic from `51.222.95.0/24` to prevent potential lateral movement.
---
Conclusion:
This IP is part of a high-risk subnet managed by OVH for Ahrefs Pte Ltd. While no direct malicious activity is detected, the subnetβs abuse density and geolocation inconsistencies warrant close monitoring. SOC teams should prioritize validating the IPβs legitimacy and assessing the subnetβs overall risk posture.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059689 |
| CIDR Block | 51.222.95.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca010-san21.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca010-san21.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:26 UTC |
| Last Seen | 2026-06-27 07:07:00 UTC |
| Profile Built | 2026-06-28 01:13:02 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 26 |
Full dossier details are available via our API.