# IP INTELLIGENCE BRIEFING
## Target: 51.195.183.128/32
Classification: Moderate Risk | Last Updated: 2026-06-14
---
EXECUTIVE SUMMARY
IP address 51.195.183.128 is assigned to OVH (ASN 16276) within the 51.195.0.0/16 block. The address resolves to ahrefs.net infrastructure in London, GB, operating as a cloud computing hosting service. Current risk assessment indicates Moderate Risk (score 40). While the IP shows no active threat indicators, the /24 subnet demonstrates elevated abuse density requiring monitoring context.
---
OWNERSHIP & NETWORK ATTRIBUTES
| Attribute | Value |
|---|---|
| ASN | 16276 (OVH) |
| Organization | Ahrefs Pte Ltd Dmytro |
| Country/Region | GB / England, London |
| Infrastructure Type | CloudCompute |
| Network Role | Cloud Hosting |
| Provider Score | 0 |
| Authority Score | 0 |
Classification Flags:
- Cloud: Yes
- CDN: No
- VPN: No
- Proxy: No
- Tor: No
- Hosting: Yes
- Residential: No
---
DNS & HOSTING INTELLIGENCE
- PTR Hostname: proxy-uk003-san128.ahrefs.net
- Forward Resolution: proxy-uk003-san128.ahrefs.net (confirmed)
- Domain: ahrefs.net
- CAA Records: Present
- Service Status: Firewalled / No Services (open ports: 0)
- SSL/TLS: No certificates detected
---
THREAT ASSESSMENT
Risk Score: 40 (Moderate)
Threat Indicators:
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- Known Campaigns: None
- Threat Persistence Days: 0
Control Plane:
- BGP Prefix: 51.195.0.0/16
- Operator Score: 0.2174 (Minimal)
- DNSBL Listed: 1 of 8 total lists
- Route Stability: False
- DNSSEC: Valid
---
SUBNET ANALYSIS (51.195.183.0/24)
Abuse Density: 0.6562 (High Abuse)
Neighbor Statistics:
- Total Siblings: 256
- Active Siblings: 193
- Threat Siblings: 168
- Inherited Risk Score: 26
Risk Distribution in /24:
- High Risk: 0
- Medium Risk: 99
- Low Risk: 1
Notable Neighbor IPs:
- 51.195.183.0: Risk 40, Authority 50
- 51.195.183.1: Risk 40, Authority 50
- 51.195.183.2: Risk 40, Authority 50
- 51.195.183.3: Risk 40, Authority 50
- 51.195.183.4: Risk 40, Authority 50
---
OBSERVATION HISTORY (21 Observations)
Recent signal history confirms:
- Infrastructure: Consistently classified as OVH cloud hosting
- Geolocation: Stable GB/London assignment
- Domain: ahrefs.net confirmed with CAA records
- Abuse Density: Consistently elevated at 0.6562
No significant changes in risk profile or threat posture observed.
---
RELATIONSHIP GRAPH
Total Relationships: 59
Primary relationship type: Same Network (OVH_282347339)
---
SECURITY RECOMMENDATIONS
Based on current risk profile and subnet context:
1. Monitoring: Continue monitoring due to high-abuse subnet context (0.6562 density).
2. Firewall: No immediate blocking required; IP is firewalled with no open services.
3. Threat Intel: Monitor for emergence of threat indicators in the /24 subnet.
4. Geographic Context: London-based infrastructure; consider regional threat landscape.
---
Analyst Notes: This IP represents legitimate cloud hosting infrastructure for ahrefs.net. The moderate risk score and high abuse density in the parent subnet warrant contextual awareness but do not indicate immediate threat activity. No defensive firewall rules recommended at this time.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk003-san128.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk003-san128.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 37% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-08 17:18:08 UTC |
| Last Seen | 2026-06-27 13:57:04 UTC |
| Profile Built | 2026-06-28 08:02:27 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 30 |
Full dossier details are available via our API.