# IP INTELLIGENCE BRIEFING
Target: 51.91.109.113/32
Date: Current Analysis
Classification: LOW RISK / DEFENSIVE CLEARANCE
## EXECUTIVE SUMMARY
IP 51.91.109.113 is a low-risk infrastructure address hosted on OVH SAS cloud infrastructure in France. The address demonstrates stable ownership with no malicious threat indicators. Neighborhood analysis shows clean subnet conditions with no active threat siblings. Standard web and SSH services are operational.
## INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| **Risk Score** | 25 (Low Risk) |
| **Provider** | OVH SAS (ASN 16276) |
| **Location** | France (FR) |
| **Infrastructure Type** | CloudCompute / Hosting |
| **DNS PTR** | 113.ip-51-91-109.eu |
| **Subnet** | 51.91.109.0/24 |
## NETWORK SERVICES
- Port 80/TCP (HTTP): Apache/2.4.10 (Debian) server banner
- Port 22/TCP (SSH): OpenSSH_6.7p1 Debian-5+deb8u8
- HTTP Version: 1.1
- Status Code: 200 OK
- HSTS: Disabled
- CSP: Not configured
## THREAT INDICATORS
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- DNSBL Lists: 1/8 (minimal impact)
- Known Campaigns: None
- Abuse Confidence Score: Not elevated
## OBSERVATION HISTORY (22 Signals)
- Stability: No ownership changes observed
- Threat Persistence: 0 days (not persistently malicious)
- Recent Activity: 2026-06-19
- Signal Types: Network classification, HTTP fingerprinting, geolocation inference
- Geolocation Confidence: 0.52 (multi-signal inference, France)
- RTT: 95-105ms average (plausible for France)
## RELATIONSHIP GRAPH (48 Relationships)
- DNS Associations: Multiple hostname entries (113.ip-51-91-109.eu)
- Network Association: VPS-SBG6 (OVH virtual private server)
- No anomalous entity links detected
## NEIGHBORHOOD ANALYSIS (51.91.109.0/24)
- Abuse Density: 0.0 (clean subnet)
- Total Siblings: 1 active
- Threat Siblings: 0
- Classification: mostly_clean
- Risk Distribution: High: 0, Medium: 0, Low: 0
## SECURITY ACTIONS & RECOMMENDATIONS
Assessment: No immediate security actions recommended. The IP demonstrates normal cloud hosting behavior with standard web and SSH services.
Suggested Firewall Policy:
- Allow traffic if legitimate business relationship exists
- Monitor for unusual outbound connections from this host
- Standard SSH access control applies (port 22)
Risk Context: This IP is classified as a multi-service host on OVH cloud infrastructure. The single DNSBL listing (8 total lists) appears to be a false positive or minor listing, as no other threat indicators are present.
## INTELLIGENCE JUDGMENT
Clearance: DEFENSIVE CLEARANCE GRANTED
Monitoring Priority: LOW
Action Required: None
This address exhibits characteristics of legitimate cloud hosting infrastructure. No defensive blocking is warranted based on current intelligence. Standard monitoring practices apply.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH SAS |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 113.ip-51-91-109.eu |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 113.ip-51-91-109.eu |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Apache/2.4.10 (Debian) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_6.7p1 Debian-5+deb8u8 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 41% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 28% | 10 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-14 07:14:53 UTC |
| Last Seen | 2026-06-28 00:34:36 UTC |
| Profile Built | 2026-06-28 18:39:21 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 28 |
Full dossier details are available via our API.