# IPDEBRIEF INTELLIGENCE BRIEFING
Target IP: 51.68.236.92/32
Classification: Moderate Risk (Score: 40)
Date: Intelligence compiled from multiple data sources
## 1. OWNERSHIP AND GEOLOCATION
The IP address is owned by OVH SAS (ASN 16276), a major French cloud hosting provider. Geolocation data indicates the address is located in France (FR) with 500km accuracy radius. The infrastructure is classified as CloudCompute and hosting infrastructure, consistent with OVH's business model.
## 2. NETWORK INFRASTRUCTURE
Services:
- Port 80/TCP: HTTP service running Apache/2.4.62 on Rocky Linux
- Port 22/TCP: SSH service running OpenSSH 8.7
DNS Resolution:
- PTR Hostname: crawl-qa99al.mj12bot.com
- Forward resolution confirmed
- No email authentication records (SPF/DMARC not configured)
Control Plane:
- BGP Prefix: 51.68.0.0/16
- DNSSEC Valid: Yes
- DNSBL Listed: 1 of 8 lists
## 3. THREAT ASSESSMENT
Current Risk Profile:
- Risk Score: 40/100 (Moderate Risk)
- No known attack campaigns correlated
- Not classified as Tor exit node, known attacker, or spam source
- Blacklist count: 0
Temporal Analysis:
- 22 total signal observations recorded
- Most recent activity: June 18, 2026 (port scans, TLS verification)
- Ownership stability: No changes observed
- Threat persistence: Single observation event
- Not flagged as persistently malicious
## 4. SUBNET NEIGHBORHOOD ANALYSIS
Subnet: 51.68.236.0/24
Abuse Density Metrics:
- Classification: High Abuse (0.625 density)
- Total Siblings: 16
- Active Siblings: 5
- Threat Siblings: 10
Neighbor Risk Distribution:
- 15 neighbors with medium risk scores (40-50)
- No high-risk neighbors identified
- Consistent authority scores (60) across neighbors
Notable Neighbor IPs:
- 51.68.236.59, .64, .68, .69: Risk Score 50
- 51.68.236.70, .71, .72, .87, .90, .91, .93, .94, .95, .114: Risk Scores 40-50
## 5. RELATIONSHIP GRAPH
Identified Associations:
- DNS Association: crawl-qa99al.mj12bot.com
- Network Affiliations: Multiple entries to OVH-DEDICATED-FO network segment
- 46 total relationship connections identified
## 6. RECOMMENDED SECURITY ACTIONS
Based on the moderate risk profile and neighborhood context, the following defensive measures are recommended:
Firewall Blocking Rules:
- iptables: `iptables -A INPUT -s 51.68.236.92 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 51.68.236.92 drop`
- Nginx: `deny 51.68.236.92;`
- pfSense: `51.68.236.92/32`
WAF Implementation:
- Cloudflare WAF: Block rule with expression `ip.src eq 51.68.236.92`
- AWS WAF: Add IP 51.68.236.92/32 to block list
Contextual Note: The high abuse density of the /24 subnet (0.625) suggests this IP may be part of a broader infrastructure with elevated abuse potential. Blocking at the network perimeter is recommended, but consider allowing traffic from this subnet for legitimate business purposes if OVH hosting is authorized.
## 7. INTELLIGENCE SUMMARY
IP 51.68.236.92 presents a moderate risk profile typical of OVH cloud hosting infrastructure. The subnet exhibits elevated abuse density with 10 of 16 neighbors flagged as threat siblings. While the target IP lacks specific threat indicators, the contextual risk from neighborhood analysis suggests defensive blocking is warranted. The DNS hostname crawl-qa99al.mj12bot.com indicates potential automated crawling behavior. Monitor for escalation in risk score or emergence of specific threat indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH SAS |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | crawl-qa99al.mj12bot.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | crawl-qa99al.mj12bot.com |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Apache/2.4.62 (Rocky Linux) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.7 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 47% | 2 | 6 |
| routing | 13% | 1 | 1 |
| services | 28% | 2 | 4 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 30% | 10 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:27 UTC |
| Last Seen | 2026-06-27 07:18:33 UTC |
| Profile Built | 2026-06-28 01:24:32 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 32 |
Full dossier details are available via our API.