IP Intelligence Briefing: 51.222.95.214
Date: 2026-06-14
---
**1. Core Profile**
- Risk Score: 50 (Moderate Risk)
- Ownership: Registered to Ahrefs Pte Ltd (OVH ASN 16276).
- Geolocation: Claimed location: Canada (QC, Montreal), but city field shows "Singapore." RTT validation flags this as plausible spoofing (minimum possible RTT for 5,598km is 112ms, but observed RTT is 28ms).
- Network Role: Hosting infrastructure (OVH cloud provider).
- Threat Indicators: No malicious activity detected (no indicators, blacklist entries, or campaigns).
---
**2. Network & Subnet Analysis**
- Subnet: 51.222.95.214/24
- Neighbor Risk:
- 73 IPs with medium risk (25β50), 27 with low risk (0β25).
- Abuse Density: 0% (no malicious activity in neighbors).
- Subnet Classification: "Mixed" (combination of legitimate and suspicious IPs).
---
**3. Historical Observations**
- First Seen: 2026-06-05
- Key Trends:
- Stable ownership (OVH) with no changes.
- No persistent malicious behavior (threat persistence days: 0).
- Geolocation anomalies persist (Singapore vs. Canada).
---
**4. Relationships & Dependencies**
- Linked Hostname: `proxy-ca010-san214.ahrefs.net` (DNS PTR record).
- BGP Details:
- Origin ASN: 16276 (OVH).
- BGP prefix: `51.222.0.0/16`.
- Route stability: Unstable (route changes in last 30 days).
- DNSSEC: Validated.
- CAA Records: Present.
---
**5. Threat & Risk Context**
- No Direct Threats: No malware, phishing, or exploit indicators.
- Indirect Risks:
- Geolocation spoofing may mask true origin.
- Subnet contains 125 threat siblings (potentialε ³θ IPs).
- Recommendation: Monitor for unusual traffic patterns or DNS changes. Verify geolocation accuracy.
---
**6. SOC Action Plan**
1. Verify Geolocation: Cross-check with external geolocation tools.
2. Monitor Subnet: Watch for spikes in traffic or new threat siblings.
3. Validate DNS: Ensure `proxy-ca010-san214.ahrefs.net` is legitimate.
4. Block Anomalies: Use firewall rules to restrict unexpected traffic to/from this subnet.
---
Tools Used: `ipdebrief_profile`, `ipdebrief_history`, `ipdebrief_relationships`, `ipdebrief_neighbors`.
Final Risk Assessment: Moderate risk due to geolocation discrepancies and subnet mix. No immediate mitigation required, but ongoing monitoring advised.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059689 |
| CIDR Block | 51.222.95.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca010-san214.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca010-san214.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 21% | 9 | 13 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-08 11:10:41 UTC |
| Last Seen | 2026-06-27 13:20:40 UTC |
| Profile Built | 2026-06-28 07:25:57 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 28 |
Full dossier details are available via our API.