INTELLIGENCE BRIEFING: 51.75.128.89
Classification: Low Risk Cloud Infrastructure | Date: 2026-06-20
---
Executive Summary
IP 51.75.128.89 is a low-risk residential hosting address from OVH SAS infrastructure in France (ASN 16276). Risk score: 25/100. No active threat indicators detected. Suitable for standard monitoring with no immediate blocking requirements.
---
Ownership & Infrastructure Profile
| Attribute | Value |
|---|---|
| **Organization** | OVH SAS |
| **ASN** | 16276 |
| **Country** | France (FR) |
| **Infrastructure Type** | CloudCompute / Hosting |
| **CIDR Block** | 51.75.0.0/16 |
| **Network Classification** | Cloud Provider |
The IP is registered to OVH's cloud hosting infrastructure with consistent ownership. DNS resolution confirms the address points to ns3131619.ip-51-75-128.eu.
---
Threat Indicators
- Risk Score: 25 (Low Risk)
- Blacklist Count: 0
- Threat Feeds: None
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Abuse Confidence: Not elevated
No active threat indicators or malicious activity observed. The IP maintains a clean reputation across all monitored feeds.
---
Network Neighborhood Analysis
Subnet: 51.75.128.89/24
| Metric | Value |
|---|---|
| **Abuse Density** | 0 (Low) |
| **Total Siblings** | 4 |
| **Active Siblings** | 3 |
| **Threat Siblings** | 4 |
Neighbor IPs:
- 51.75.128.50 (Risk: 25, Authority: 60)
- 51.75.128.81 (Risk: 25, Authority: 60)
- 51.75.128.94 (Risk: 25, Authority: 60)
The /24 subnet exhibits low abuse density with consistent risk profiles across neighboring addresses, indicating standard OVH cloud hosting operations.
---
Service Exposure
- Port 22/TCP (SSH): Open (OpenSSH_9.6p1 Ubuntu-3ubuntu13.16)
- HTTP/HTTPS: No service detected
- TLS Certificate: Not present
Standard cloud hosting configuration with SSH access enabled.
---
Historical Observations
Recent signal history confirms stable, low-risk behavior:
- Classification: "mostly_clean" (abuse_density: 1)
- Threat Persistence: 0 days
- Ownership Changes: 0
- Malicious Activity: None observed
Geolocation inference places the IP in France with 500km accuracy radius. No significant changes in risk profile over observation period.
---
Intelligence Assessment
This address represents standard OVH cloud hosting infrastructure with no malicious indicators. The low risk score (25), zero blacklist presence, and clean neighborhood profile support continued monitoring rather than blocking.
Recommended Action: Monitor for any changes in threat indicators. No immediate defensive action required.
Priority: Low
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH SAS |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ns3131619.ip-51-75-128.eu |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ns3131619.ip-51-75-128.eu |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 15:27:11 UTC |
| Last Seen | 2026-06-28 07:41:10 UTC |
| Profile Built | 2026-06-29 01:56:26 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.