IP Intelligence Briefing: 51.195.183.192
Date: 2026-06-09
---
**1. Risk Profile**
- Risk Score: 40 (Moderate Risk)
- Provider: OVH (ASN 16276)
- Organization: Ahrefs Pte Ltd (registered with ARIN)
- Geolocation: London, England, UK (inferred via multi-signal geolocation with 750km accuracy radius).
- Network Role: Cloud compute instance (OVH infrastructure), no residential/mobile indicators.
- Threat Indicators: No direct malicious activity detected (no blacklists, spam, or known attacker associations).
---
**2. Observation History**
- Latest Observations (2026-06-09):
- Geolocation inferred via multi-signal methods (confidence: 28%).
- Network classification as "high_abuse" subnet (abuse density: 63.67%).
- DNS association with `proxy-uk003-san192.ahrefs.net` (Ahrefs infrastructure).
- Trend: No significant changes in risk signals over the last 30 days.
---
**3. Relationships & Associations**
- Network: Linked to OVH network (ASN 16276) and subnet `51.195.183.192/24`.
- DNS: Associated with `proxy-uk003-san192.ahrefs.net` (Ahrefs domain).
- Subnet Abuse: Parent subnet (`51.195.0.0/16`) classified as "high_abuse" with 163 malicious siblings.
---
**4. Subnet Neighborhood**
- Subnet: `51.195.183.192/24` (256 total IPs).
- Abuse Density: 63.67% (163 malicious siblings, 98 medium-risk, 2 low-risk).
- Key Neighbors:
- IPs with risk scores of 40 (same as target).
- Subnet flagged for high abuse, suggesting potential lateral movement risks.
---
**5. Recommendations**
- Monitoring:
- Watch the `51.195.183.192/24` subnet for unusual traffic patterns due to high abuse density.
- Validate DNS associations (`proxy-uk003-san192.ahrefs.net`) for potential command-and-control (C2) activity.
- Segmentation:
- Consider isolating cloud compute instances (OVH) to limit lateral movement.
- Firewall Rules:
- Block all traffic from the subnet `51.195.183.192/24` if not explicitly required.
---
Conclusion:
The IP is part of a cloud infrastructure used by Ahrefs, with no direct malicious indicators. However, its subnet exhibits high abuse density, warranting closer scrutiny. SOC teams should prioritize monitoring network behavior and limiting exposure to this subnet.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk003-san192.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk003-san192.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 38% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 26% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 09:13:25 UTC |
| Last Seen | 2026-06-28 18:47:51 UTC |
| Profile Built | 2026-06-29 06:53:02 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.