IPDebrief

51.79.68.87

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 51.79.68.87

## Executive Summary

The IP address 51.79.68.87 was analyzed as part of routine network intelligence gathering. The system classified this address as low risk with an overall risk score of 25. The IP operates within OVH Hosting's cloud infrastructure and shows no active threat indicators.

## Ownership and Network Classification

The system identified the IP as belonging to OVH Hosting, Inc. (ASN 16276) within the VPS-BHS6 CIDR block (51.79.64.0/21). Network classification confirmed the infrastructure type as cloud computing with hosting services enabled. The IP is not classified as a CDN, VPN, proxy, or residential connection.

## Geolocation Analysis

The system recorded the geolocation as Canada (CA). However, geolocation validation revealed inconsistencies: the geo_plausible flag was set to false, and RTT measurements showed a violation where the observed RTT of 26.0ms was less than the minimum possible 121.6ms for the claimed distance of 6082km. The system recorded an accuracy radius of 3000km, indicating limited geolocation precision.

## Threat Indicators

The system found no active threat indicators. The IP is not registered as a Tor exit node, known attacker, or spam source. Blacklist enumeration returned zero counts across threat feeds. The abuse confidence score remained null with no threat persistence observed.

## DNS and Hostname Resolution

Reverse DNS resolution returned mail.sbiwee.com. Forward DNS confirmation failed, and the system recorded one forward resolution. The domain sbiwee.com showed no SPF or DMARC records with a TXT record count of zero. TLS certificate analysis revealed a Let's Encrypt certificate (CN=E7, O=Let's Encrypt, C=US) issued for sbiwee.com with SAN entries including www.sbiwee.com.

## Service Fingerprint

The system identified three open ports: TCP/80 (HTTP), TCP/443 (HTTPS), and TCP/22 (SSH). Server banner analysis revealed nginx/1.22.1. The HTTPS implementation showed HTTP Strict Transport Security (HSTS) enabled but did not implement Content Security Policy (CSP). HTTP/2 was not observed.

## Neighborhood Analysis

The /24 subnet (51.79.68.0/24) showed zero abuse density and was classified as clean. The system recorded one total sibling IP with one active sibling and zero threat siblings. Risk distribution across the neighborhood showed no high, medium, or low risk classifications.

## Historical Observations

The system captured 25 historical observations across multiple signal types. Recent observations (2026-08-05) consistently identified the infrastructure as cloud hosting within OVH's network. Geolocation signals showed mixed confidence levels ranging from 0.18 to 0.90, with some observations inferring the country as Canada with low confidence (0.175). RTT validation consistently flagged violations with observed values significantly below minimum plausible thresholds.

## Relationship Graph

The system identified 21 relationships total. Network relationships mapped to VPS-BHS6 (OVH infrastructure). DNS associations consistently linked to mail.sbiwee.com across multiple relationship entries. No organizational or certificate relationships beyond the DNS association were observed.

## Recommended Actions

The system generated no specific security action recommendations. The risk score of 25 and absence of threat indicators suggest this IP does not require immediate blocking or firewall rule implementation at this time.

---

*This intelligence briefing was generated from IPDebrief tool outputs as of the most recent data retrieval. All information presented is factual and derived from system observations.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡จ๐Ÿ‡ฆ Canada
Regionโ€”
CityNew York
Timezoneโ€”
Latitudeโ€”
Longitudeโ€”

๐Ÿข Ownership & Registration

OrganizationOVH Hosting, Inc.
ASNAS16276
Network NameVPS-BHS6
CIDR Block51.79.64.0/21
RIRARIN
CountryCanada
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRmail.sbiwee.com
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesmail.sbiwee.com

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeSingle-Service Host
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Servernginx/1.22.1
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_10.0p2 Debian-7~bpo12+1

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
30%
23
routing
13%
11
services
30%
23
ownership
27%
23
reputation
15%
12
geolocation
32%
23
Overall24%1015
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Claimed geolocation contradicts RTT physics measurement

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-21 06:47:38 UTC
Last Seen2026-08-13 06:45:10 UTC
Profile Built2026-08-12 15:57:21 UTC
Data FreshnessLive
Signal Types24
Total Observations25
๐Ÿ” 24 signal types ยท 25 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.