IP Threat Intelligence Briefing: 51.222.95.77
Date: 2026-06-15
---
**1. IP Profile**
- Risk Score: Moderate (40/100)
- Ownership: Owned by OVH (AS16276), registered to "Dmytro, Ahrefs Pte Ltd"
- Geolocation:
- Country: Canada (QC, Quebec)
- Geo Validation: Flagged as implausible (RTT anomaly for distance).
- Network Role: CloudCompute infrastructure (OVH-hosted, no residential/mobile signals).
- Threat Indicators: No direct malicious activity detected (no indicators, blacklists, or campaigns).
---
**2. Observation History**
- Recent Activity (Last 30 Days):
- 1 observation of high-risk subnet (51.222.95.77/24) with abuse density 59.77%.
- 1 threat signal flagged via AlienVault OTX (reputation score 0, 1 pulse detected).
- Trend: Stable risk profile; no escalation in threats or scans.
---
**3. Network Relationships**
- Subnet: 51.222.95.0/24
- Key Associations:
- Linked to OVH-CUST-281059689 (customer ASN).
- DNS: Resolves to `proxy-ca010-san77.ahrefs.net` (associated with Ahrefs).
- BGP: Origin ASN 16276, route stability: unstable (route changes in last 30 days).
---
**4. Neighborhood Analysis**
- Subnet Abuse Density: 59.77% (classified as high_abuse).
- Neighbor Risk Distribution:
- 78 IPs with medium risk (score 40โ50).
- 22 IPs with low risk.
- 153 neighbors flagged as threat siblings (potential abuse or malicious activity).
---
**5. Recommended Actions**
- Firewall Rules:
- Block IP via:
```bash
iptables -A INPUT -s 51.222.95.77 -j DROP
nft add rule inet filter input ip saddr 51.222.95.77 drop
```
- Configure WAF rules (Cloudflare/AWS) to block the IP.
- Monitoring:
- Watch subnet 51.222.95.0/24 for abnormal traffic.
- Verify DNS resolution ties to Ahrefs (potential proxy/service).
- Investigation:
- Cross-check with Ahrefs infrastructure for legitimate use cases.
- Validate geo-plausibility anomalies (e.g., Singapore vs. Quebec).
---
Conclusion:
The IP is part of a high-abuse subnet hosted by OVH, with no direct malicious activity detected. However, its association with a high-risk subnet and potential proxy services warrants monitoring. Use the provided firewall rules to mitigate risk while investigating further.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059689 |
| CIDR Block | 51.222.95.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca010-san77.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca010-san77.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 21% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 09:13:33 UTC |
| Last Seen | 2026-06-28 18:58:35 UTC |
| Profile Built | 2026-06-29 07:02:11 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.