# IP Intelligence Briefing: 51.77.201.73/32
Classification: Moderate Risk Cloud Infrastructure Host
Date: Analysis based on current intelligence data
Risk Score: 50/100
## Executive Summary
IP 51.77.201.73 is a cloud computing host operated by OVH SAS within the PCI-SBG6 network block (51.77.200.0/22) in France. The IP hosts a VPS instance (vps-8242e103.vps.ovh.net) running nginx/1.18.0 with standard web services. While no active threat campaigns were detected, the IP carries a moderate risk profile with DNSBL listings present in historical observations.
## Technical Profile
| Attribute | Value |
|---|---|
| **Organization** | OVH SAS (ASN: 16276) |
| **Network** | PCI-SBG6, 51.77.200.0/22 |
| **Geolocation** | France, Europe/Paris timezone |
| **Infrastructure** | Cloud Compute / Web Hosting |
| **PTR Hostname** | vps-8242e103.vps.ovh.net |
| **Status Code** | 200 OK |
## Services & Fingerprinting
- Open Ports: TCP/80 (HTTP), TCP/443 (HTTPS), TCP/22 (SSH)
- Web Server: nginx/1.18.0 (Ubuntu)
- TLS Certificate: Let's Encrypt (CN=eqwanza.fr)
- SPF: Configured (v=spf1 include:mx.ovh.com -all)
- DMARC: Not configured
## Threat Indicators
- Current Blacklist Count: 0
- DNSBL Listed: 2 of 8 total lists
- Known Campaigns: None detected
- Tor Exit/Proxy: Negative
- Abuse Confidence Score: Not assigned
## Neighborhood Analysis
Subnet 51.77.201.0/24 shows clean classification with zero abuse density. No threat siblings detected in the immediate /24 neighborhood. The IP appears isolated from coordinated abuse activity within its subnet.
## Historical Observations
26 total observations recorded. Recent monitoring indicates:
- DNSBL listings with high severity classification observed
- SPF record present but DMARC absent
- No persistent malicious behavior patterns detected
- Ownership stability maintained with zero changes
## Recommended Actions
Based on risk score 50, the following controls are recommended:
| Platform | Recommended Rule |
|---|---|
| iptables | `iptables -A INPUT -s 51.77.201.73 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 51.77.201.73 drop` |
| nginx | `deny 51.77.201.73;` |
| Cloudflare WAF | Block rule with expression: `ip.src eq 51.77.201.73` |
| AWS WAF | IPSet rule for 51.77.201.73/32 |
## Intelligence Notes
The IP hosts a legitimate VPS configuration for the domain eqwanza.fr. Historical DNSBL listings may indicate past abusive activity or false positives common in shared cloud infrastructure. The absence of coordinated threat indicators and clean neighborhood data suggests limited current threat relevance. SOC teams may consider this IP for monitoring if inbound traffic patterns indicate scanning or exploitation attempts, though no active campaigns were identified.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH SAS |
| ASN | AS16276 |
| Network Name | PCI-SBG6 |
| CIDR Block | 51.77.200.0/22 |
| RIR | ARIN |
| Country | FR |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vps-8242e103.vps.ovh.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vps-8242e103.vps.ovh.net |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | 2/2 domains |
| DMARC | 1/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.18.0 (Ubuntu) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16 |
๐ TLS Certificate
| SANs | eqwanza.frwww.eqwanza.fr |
| Valid From | 2026-06-24T03:53:36+00:00 |
| Valid Until | 2026-09-22T03:53:35+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 05CFE05F35FD57421F2E0D72ED2DE2708B7A |
| Thumbprint | 27C290100BA0C71CB9FF07CAF8A28FA579731341 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 42% | 2 | 4 |
| routing | 17% | 1 | 1 |
| services | 35% | 2 | 3 |
| ownership | 35% | 2 | 3 |
| reputation | 32% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 32% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-04 05:43:06 UTC |
| Last Seen | 2026-08-13 06:16:20 UTC |
| Profile Built | 2026-08-13 06:26:08 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 27 |
Full dossier details are available via our API.