## IP Intelligence Briefing: 51.222.96.124/32
Date: Current Investigation
Classification: Moderate Risk
Risk Score: 50/100
---
Executive Summary
IP address 51.222.96.124 is hosted on OVH infrastructure (ASN 16276) within a cloud computing environment. The asset presents moderate risk due to geolocation inconsistencies and minimal operator reputation scores. No active threat indicators or known campaigns detected.
---
Ownership & Infrastructure
- ASN: 16276 (OVH)
- Organization: OLEKSANDR, GUTNIK
- Network Block: 51.222.96.0/25
- Infrastructure Type: CloudCompute (Hosting)
- Geolocation: Canada (CA), Quebec region with Estonia city designation
- Geolocation Validity: Compromised โ RTT analysis indicates 5597.9km distance claim with observed minimum RTT of 28ms, violating the theoretical minimum of 112ms for claimed distance
---
Network Services
- HTTP (Port 80): Apache/2.4.37 on AlmaLinux platform
- SSH (Port 22): OpenSSH_8.0
- DNS PTR: mks-sis-ujs.smarthomesshields.com
- HTTP Status: 403 Forbidden
- Security Headers: Missing HSTS, CSP, and Referrer-Policy
---
Threat Assessment
- Abuse Confidence Score: Not calculated
- Blacklist Status: 0 blacklist entries
- Tor/Proxy: Not a Tor exit node, proxy, or CDN
- Known Campaigns: None identified
- Threat Persistence: Not persistently malicious
- Control Plane Risk: DNSBL listed on 2 of 8 lists; route stability compromised
---
Historical Observations
24 observations recorded with most recent activity on June 19, 2026. Historical signals show:
- Geolocation inconsistencies between Canada and Estonia designations
- Single threat observation in history
- No evidence of escalating risk profile over time
---
Neighborhood Analysis
Subnet 51.222.96.0/24 shows:
- Abuse Density: 0 (mostly clean)
- Active Siblings: 1 (the target IP)
- Threat Siblings: 1
- Risk Distribution: No high or medium risk neighbors detected
---
Security Recommendations
Based on risk profile of 50/100, the following firewall rules are recommended:
iptables:
```
iptables -A INPUT -s 51.222.96.124 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 51.222.96.124 drop
```
nginx:
```
deny 51.222.96.124;
```
Cloudflare WAF:
```
Block 51.222.96.124 โ IPDebrief risk score 50
```
AWS WAF:
```
Addresses: 51.222.96.124/32
Description: IPDebrief risk 50
```
---
Analysis Notes
This IP represents a cloud-hosted infrastructure asset with moderate risk characteristics. The geolocation discrepancy between claimed Canada/Estonia location and actual RTT measurements suggests potential data quality issues. While no active malicious indicators were detected, the operator score of 0.1304 (Minimal) combined with DNSBL listings warrants monitoring. Recommended actions should be validated against additional signals before implementation in production environments.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OLEKSANDR, GUTNIK |
| ASN | AS16276 |
| Network Name | OVH-CUST-199302644 |
| CIDR Block | 51.222.96.0/25 |
| RIR | ARIN |
| Country | Canada |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | mks-sis-ujs.smarthomesshields.com |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | mks-sis-ujs.smarthomesshields.com |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | Apache/2.4.37 |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 32% | 2 | 3 |
| ownership | 15% | 2 | 2 |
| reputation | 27% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 25% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-12 03:44:12 UTC |
| Last Seen | 2026-06-27 21:01:22 UTC |
| Profile Built | 2026-06-28 15:06:16 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 28 |
Full dossier details are available via our API.