# THREAT INTELLIGENCE BRIEFING
IP Address: 51.195.183.147/32
Classification: Moderate Risk (Score: 40/100)
Date: Current Analysis
---
## EXECUTIVE SUMMARY
IP 51.195.183.147 operates within OVH cloud infrastructure and resolves to aresnet domain infrastructure. The IP shows moderate risk with elevated neighborhood abuse density. No active malicious indicators or known campaign associations detected.
---
## OWNERSHIP & GEOLOCATION
- Organization: Ahrefs Pte Ltd Dmytro
- ASN: 16276 (OVH)
- Location: London, England, GB
- Network Block: 51.195.0.0/16
- Infrastructure Type: Cloud Compute (Hosting enabled)
---
## NETWORK CHARACTERISTICS
- DNS Resolution: proxy-uk003-san147.ahrefs.net
- Registered Domain: ahrefs.net
- Service Status: Firewalled / No Services (No open ports detected)
- TLS/HTTP: No active services exposed
---
## THREAT INDICATORS
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Status: Listed on 1 of 8 DNSBLs
- Campaign Associations: None identified
- Abuse Confidence: Data insufficient for scoring
---
## NEIGHBORHOOD ANALYSIS
Subnet: 51.195.183.0/24
- Abuse Density: 0.668 (High Abuse Classification)
- Total Siblings: 256
- Active Siblings: 195
- Threat Siblings: 171
- Inherited Risk Score: 26
The subnet exhibits elevated abuse activity with approximately 67% of active IPs flagged as threats. However, this target IP maintains a risk score of 40, positioned in the medium-risk category relative to neighborhood peers.
---
## OBSERVATION HISTORY
- Total Observations: 23 signals recorded
- Recent Operator Score: 0.2174 (Minimal)
- Threat Persistence: No persistent malicious activity detected
- Ownership Changes: None recorded
- Certificate Signals: Present (crt-sh source)
The IP demonstrates stable operational behavior with no degradation in risk profile over the observation window.
---
## RELATIONSHIP NETWORK
- Total Relationships: 41
- Primary Association: Same Network (OVH_282347339)
- Related Entities: Multiple network-level associations within OVH infrastructure
---
## RECOMMENDATIONS
1. Allow with Monitoring: Risk score of 40 indicates moderate threat level suitable for permitted traffic with logging
2. No Blocking Required: No active malicious indicators present
3. Neighborhood Awareness: Monitor subnet 51.195.183.0/24 for coordinated abuse patterns
4. DNSBL Verification: Investigate reason for single DNSBL listing if security policy requires
---
Status: Active Monitoring Recommended
Classification: Moderate Risk Infrastructure Asset
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk003-san147.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk003-san147.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 03:23:24 UTC |
| Last Seen | 2026-06-28 06:32:15 UTC |
| Profile Built | 2026-06-29 00:37:21 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.