## IP Intelligence Briefing: 51.68.107.148
Classification: MODERATE RISK | Date: Current | Report Type: Threat Intelligence
Executive Summary
IP 51.68.107.148 is a French cloud hosting IP (OVH SAS) presenting moderate risk (score: 50). The address is associated with multi-service hosting infrastructure and exhibits minimal immediate threat indicators. While not actively malicious, the IP resides in a subnet with elevated abuse density and is DNS-resolved to a botnet-related hostname pattern.
Ownership & Infrastructure
- Provider: OVH SAS (ASN 16276)
- Infrastructure Type: CloudCompute / Hosting
- Geolocation: France (FR) โ Europe/Paris timezone
- BGP Prefix: 51.68.0.0/16
- Registration: ARIN (registration date unavailable)
Threat Profile
- Risk Score: 50 (Moderate)
- Blacklist Status: Listed on 2 of 8 DNSBLs
- Known Threats: None currently identified
- Tor Exit/Proxy: Negative
- Campaign Affiliation: None detected
- Operator Classification: Basic (0.2609)
Network Services
- Port 80 (HTTP): Apache/2.4.62 (Rocky Linux)
- Port 22 (SSH): OpenSSH_8.7
- DNS Resolution: crawl-7es772.mj12bot.com
- HTTP Status: 200 OK
- Fingerprint: Apache/2.4.62 server banner confirmed
Neighborhood Analysis (51.68.107.0/24)
- Abuse Density: 0.3125 (Elevated)
- Subnet Classification: Mixed
- Total Siblings: 16
- Active Siblings: 12
- Threat Siblings: 5
- Risk Distribution: High: 0, Medium: 9, Low: 6
Historical Observations (25 total signals)
Recent activity from June 25โ27, 2026 indicates:
- Consistent HTTP fingerprinting (Apache/2.4.62)
- Geolocation inference: France
- Subnet abuse density monitoring: 0.3125
- No significant threat persistence detected
Relationship Graph (78 relationships)
- DNS Associations: crawl-7es772.mj12bot.com (repeated)
- Network: OVH-DEDICATED-FO
- Correlated Entities: Multiple hostname/network associations
Recommended Actions
1. Monitoring: Flag for passive monitoring due to elevated subnet abuse density (31.25%)
2. Threat Hunting: Investigate DNS resolution pattern (crawl-*) for potential botnet activity
3. Allowlisting/Blocklisting: No immediate action required; monitor blacklist status changes
4. Subnet Context: Consider broader subnet analysis (51.68.107.0/24) for correlated threats
Risk Assessment
The IP presents moderate risk primarily due to:
- Hosting infrastructure type (multi-service)
- DNS association with botnet-style hostname (crawl-*)
- Subnet abuse density above baseline
- DNSBL listings (2/8)
No active malicious indicators detected. Recommend continued monitoring with standard logging.
---
Data Sources: IPDebrief Intelligence Platform | Analysis Time: Current
Classification: SOC-Ready Intelligence
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH SAS |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | crawl-7es772.mj12bot.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | crawl-7es772.mj12bot.com |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Apache/2.4.62 (Rocky Linux) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.7 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 26% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 27% | 1 | 3 |
| geolocation | 34% | 2 | 3 |
| Overall | 25% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-08 23:18:41 UTC |
| Last Seen | 2026-06-27 14:39:16 UTC |
| Profile Built | 2026-06-28 14:44:21 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 29 |
Full dossier details are available via our API.