# IP Intelligence Briefing: 51.195.183.153
## Executive Summary
IP address 51.195.183.153 was classified as moderate risk (risk score: 40) during observation. The address resolves to infrastructure operated by Ahrefs Pte Ltd Dmytro (ASN 16276, OVH provider) with geolocation data indicating London, England. While the IP itself shows no direct threat indicators, the /24 subnet demonstrated elevated abuse density (0.7656), requiring contextual risk assessment.
## Technical Profile
Ownership and Provider:
- Organization: Ahrefs Pte Ltd Dmytro
- ASN: 16276
- Provider: OVH (cloud infrastructure)
- Registration: ARIN registry
- IP Classification: Cloud/Hosting infrastructure
Geolocation:
- Country: Great Britain (GB)
- Region: England
- City: London
- Timezone: Europe/London
- Geographic accuracy radius: 750 km
Network Services:
- Open ports: None detected
- DNS Resolution: proxy-uk003-san153.ahrefs.net (ahrefs.net)
- Forward confirmed: No
- TLS Certificate: None observed
- No HTTP services or banner data captured
## Threat Assessment
Current Risk Indicators:
- Overall risk score: 40 (moderate)
- Blacklist count: 0
- Tor exit node: No
- Known attacker: No
- Spam source: No
- DNSBL listings: 1 of 8 lists
- Operator score: 0.2174 (minimal)
Threat Feeds:
- No active threat indicators
- No known campaigns correlated
- No evidence of persistent malicious behavior
## Neighborhood Context
Subnet Analysis (51.195.183.0/24):
- Total sibling IPs: 256
- Active siblings: 225
- Threat siblings: 196
- Abuse density classification: HIGH ABUSE (0.7656)
- Inherited risk from subnet: 30
Risk Distribution in /24:
- High risk: 0 IPs
- Medium risk: 60 IPs
- Low risk: 40 IPs
## Historical Observations
Analysis of 26 observation records indicates:
- Most recent activity: 2026-06-28T06:32:59Z
- Consistent DNS resolution to ahrefs.net domain
- Stable provider classification (OVH cloud compute)
- Historical abuse density remained consistent at 0.7656
## Recommended Actions
Firewall and Filtering Rules:
- iptables: DROP traffic from 51.195.183.153
- nftables: DROP rule for source address 51.195.183.153
- nginx: DENY directive for the IP
- pfSense: Add to block list (51.195.183.153/32)
- Cloudflare WAF: Block with risk score 40
- AWS WAF: Block address 51.195.183.153/32
## Assessment Notes
The IP address belongs to Ahrefs infrastructure, a legitimate SEO analytics service provider. However, the high-abuse subnet environment suggests shared hosting infrastructure commonly used across multiple tenants. The moderate risk score (40) reflects the elevated neighborhood abuse density rather than direct malicious activity from this specific IP. SOC teams should weigh the legitimate organizational affiliation against the subnet's historical abuse patterns when determining filtering policy. No immediate blocking is required if legitimate business use is confirmed, but monitoring is recommended given the neighborhood's elevated abuse profile.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk003-san153.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk003-san153.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 22% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 03:23:24 UTC |
| Last Seen | 2026-06-28 06:32:35 UTC |
| Profile Built | 2026-06-29 00:37:21 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.