# IP INTELLIGENCE BRIEFING
Target: 51.222.95.245/32
Date: 2026-06-18
Classification: Moderate Risk (Score: 40)
---
## EXECUTIVE SUMMARY
IP 51.222.95.245 is a cloud-hosting endpoint associated with OVH infrastructure (ASN 16276, Org: Dmytro, Ahrefs Pte Ltd). While the IP itself shows no open services or active threat indicators, it resides within a subnet exhibiting high abuse density (0.7266). The endpoint resolves to hostnames under the ahrefs.net domain, suggesting legitimate web infrastructure, but the high-risk neighborhood warrants monitoring.
---
## OWNERSHIP & INFRASTRUCTURE
- ASN: 16276 (OVH)
- Organization: Dmytro, Ahrefs Pte Ltd
- CIDR Block: 51.222.95.0/24
- Infrastructure Type: CloudCompute / Hosting
- DNS Resolution: proxy-ca010-san245.ahrefs.net (ahrefs.net)
- Network Classification: Cloud, Hosting (firewalled/no services detected)
---
## GEOLOCATION ANALYSIS
- Reported Location: CA (Canada), QC region
- Geolocation Confidence: Low (3000km accuracy radius)
- Geo-Validation: Inconsistent data reported; RTT analysis indicates 5597.9km distance from probe location
- Assessment: Geolocation data unreliable; trust only network-level routing information
---
## THREAT INDICATORS
- Risk Score: 40 (Moderate)
- Abuse Confidence: Not applicable (no active indicators)
- Blacklist Status: Listed on 8 DNSBLs, 1 general blacklist
- Campaign Activity: None detected
- Tor/Proxy/VPN: False for all categories
- Known Attacker: False
---
## NEIGHBORHOOD ANALYSIS (51.222.95.0/24)
- Abuse Density: 0.7266 (HIGH)
- Classification: high_abuse
- Subnet Statistics:
- Total Siblings: 256
- Active Siblings: 232
- Threat Siblings: 186
- Risk Distribution: 100 medium-risk neighbors sampled
- Inherited Risk Score: 29
- Assessment: Subnet exhibits elevated abuse activity; 72.66% of IP range flagged for abuse indicators
---
## OBSERVATION HISTORY
- Total Signals: 22 observations recorded
- Recent Activity: 2026-06-18 signals show consistent cloud/hosting classification
- Threat Persistence: None detected (0 threat observation days)
- Ownership Stability: No ownership changes detected
- Trend: Stable infrastructure classification with no emerging threat patterns
---
## RELATIONSHIP GRAPH
- Total Relationships: 48 entries
- Primary Associations: Same Network (OVH-CUST-281059689)
- Correlated Entities: Limited to network-level associations
- No cross-network or organizational links identified
---
## RECOMMENDED ACTIONS
1. Firewall Rules: No immediate blocking required; IP shows no active malicious services
2. Monitoring: Continue passive observation of subnet-level abuse trends
3. Contextual Intelligence: Ahrefs infrastructureβlegitimate SEO analytics company; false positives possible
4. Threat Intel Integration: Monitor DNSBL listings for reputation changes
5. Block Decision: DEFERβno evidence of active compromise; neighborhood risk warrants awareness but not immediate action
---
## CONCLUSION
IP 51.222.95.245 represents moderate-risk cloud infrastructure associated with legitimate Ahrefs hosting. While the immediate endpoint shows no malicious activity, the subnet's high abuse density (0.7266) and 186 identified threat siblings warrant continued monitoring. SOC teams should track neighborhood-level indicators for potential lateral threat expansion while avoiding premature blocking of legitimate infrastructure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059689 |
| CIDR Block | 51.222.95.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca010-san245.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca010-san245.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 22% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 23% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:26 UTC |
| Last Seen | 2026-06-27 07:08:30 UTC |
| Profile Built | 2026-06-28 01:15:18 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 25 |
Full dossier details are available via our API.