IP INTELLIGENCE BRIEFING: 51.91.177.13
Classification: Moderate Risk (Score: 55/100)
Classification Date: Current Assessment
Data Sources: IPDebrief Intelligence Platform
---
**Ownership & Infrastructure**
- Organization: OVH Hosting Limited (ASN: 16276)
- Network Block: 51.91.0.0/16 (BGPPrefix: 51.91.0.0/16)
- Infrastructure Type: Cloud Compute / Hosting Infrastructure
- Geolocation: Ireland (IE), Dublin timezone
- Service Purpose: Single-Service Host
**Technical Profile**
- DNS Resolution: info13.nuboshige.com (Forward confirmed)
- Open Services: SSH (Port 22/TCP) - OpenSSH_10.0p2 Debian-7
- TLS Certificate: Not detected
- HTTP Services: None detected
**Threat Indicators**
- Blacklist Status: Listed on 3 of 8 DNSBLs
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Campaign Correlation: None detected
**Subnet Analysis (51.91.177.0/24)**
- Abuse Density: 33.33%
- Total Siblings: 3
- Threat Siblings: 1 (51.91.177.11 - Risk: 55)
- Active Siblings: 1
- Classification: Mostly Clean
**Observation History**
- Total Observations: 24
- Recent Activity: June 2026
- Threat Persistence: 0 days
- Ownership Changes: 0 (Stable)
- Threat Observation Count: 1
**Security Recommendations**
Immediate Actions:
1. Block at Edge: Deploy drop rules for 51.91.177.13/32
2. Enhanced Logging: Increase verbosity for traffic from this IP
3. Monitor Subnet: Watch sibling IPs 51.91.177.11 and 51.91.177.30 (both risk: 55)
Firewall Rules:
- iptables: `iptables -A INPUT -s 51.91.177.13 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 51.91.177.13 drop`
- Cloudflare WAF: Block with expression `ip.src eq 51.91.177.13`
- AWS WAF: Add to block list as `51.91.177.13/32`
Context:
The elevated risk score (55) is primarily attributed to the IP's classification as hosting infrastructure rather than confirmed malicious activity. The subnet shows moderate abuse density with one confirmed threat sibling. No persistent malicious behavior has been observed. Enhanced monitoring recommended due to DNSBL listings and hosting infrastructure role.
Analyst Note: Verify against internal threat intelligence before implementing blocking. Consider geographic-based analysis if traffic originates from non-business locations.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH Hosting Limited |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | info13.nuboshige.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | info13.nuboshige.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_10.0p2 Debian-7+deb13u4 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-24 18:41:31 UTC |
| Last Seen | 2026-06-29 00:40:23 UTC |
| Profile Built | 2026-06-29 06:42:37 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.