## IP INTELLIGENCE BRIEFING: 51.222.95.89/32
Classification: Moderate Risk (Score: 40/100) | Provider: OVH SAS | ASN: 16276
Executive Summary
IP 51.222.95.89 is a cloud-hosted infrastructure address registered to Ahrefs Pte Ltd under OVH SAS. While the IP itself shows no direct threat indicators, it resides within a subnet exhibiting high abuse density (0.7227) with 185 of 256 sibling IPs classified as threats. Geographic validation anomalies detected.
Ownership & Infrastructure
- Organization: Dmytro, Ahrefs Pte Ltd (OVH-CUST-281059689)
- Network Block: 51.222.95.0/24
- Infrastructure Type: Cloud Compute / Hosting
- PTR Hostname: proxy-ca010-san89.ahrefs.net
- Service Status: Firewalled / No Services Detected
Geolocation Anomalies
Reported location shows Canada (QC) with Singapore city designation. RTT validation failure detected: measured 25ms RTT against minimum possible 112ms for 5,598km distance. This discrepancy suggests either misconfigured geolocation data or spoofed origin information.
Threat Context
- Direct Threat Indicators: None (not known attacker, not spam source, not Tor exit)
- DNSBL Status: Listed on 1 of 8 threat feeds
- Subnet Risk Profile: High Abuse Classification
- 206 active siblings in /24
- 185 threat siblings identified
- Abuse density: 0.7227 (elevated)
- Historical Signals: 19 observations recorded. Recent activity includes threat pulses detected on 2026-06-15.
Network Reputation
- Operator Score: 0.2174 (Minimal)
- Route Stability: False (routing changes observed)
- BGP Prefix: 51.222.0.0/16
- Campaign Correlation: No active campaign matches
Recommended Actions
Firewall blocking recommended due to subnet-level risk concentration:
```bash
# iptables
iptables -A INPUT -s 51.222.95.89 -j DROP
# nftables
nft add rule inet filter input ip saddr 51.222.95.89 drop
# Cloudflare WAF
Expression: ip.src eq 51.222.95.89 โ Action: Block
# AWS WAF
Addresses: 51.222.95.89/32 โ Action: Block
```
Intelligence Assessment
The IP exhibits moderate risk primarily through proximity to high-abuse neighbors rather than autonomous malicious activity. The subnet classification as "high_abuse" with significant threat sibling concentration warrants defensive posture. Geographic inconsistencies require additional verification. SOC teams should monitor for outbound connections from this IP to determine if it's being compromised or used as a proxy for command-and-control communications.
Priority: Medium โ Block at perimeter, monitor for activity patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059689 |
| CIDR Block | 51.222.95.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca010-san89.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca010-san89.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 39% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 22% | 1 | 2 |
| geolocation | 39% | 2 | 3 |
| Overall | 24% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 09:37:56 UTC |
| Last Seen | 2026-06-28 08:54:26 UTC |
| Profile Built | 2026-06-29 02:59:06 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.