INTELLECTUAL PROPERTY INTELLIGENCE BRIEFING
Target: 51.195.183.195/32
Date: June 26, 2026
Classification: Low Risk / Cloud Infrastructure
---
EXECUTIVE SUMMARY
IP address 51.195.183.195 is a cloud compute infrastructure endpoint operated by OVH (ASN 16276) under the organization Ahrefs Pte Ltd Dmytro. The IP resolves to the domain ahrefs.net with hostname proxy-uk003-san195.ahrefs.net and is geolocated to London, England. Current risk assessment indicates Low Risk status with a risk score of 25. No active services, open ports, or threat indicators were detected during profiling.
---
NETWORK CHARACTERIZATION
Infrastructure Type: CloudCompute
Provider: OVH (ASN 16276)
Network Block: 51.195.0.0/16 (BGP prefix)
Geolocation: London, GB (England)
DNS Resolution: proxy-uk003-san195.ahrefs.net (ahrefs.net)
The IP shows no open ports and no active HTTP/TLS services. The network role indicates firewalled configuration with no public-facing services detected. The IP is not classified as Tor exit node, CDN, VPN, proxy, or residential.
---
THREAT INDICATORS ANALYSIS
Current Threat Profile:
- Risk Score: 25/100 (Low Risk)
- Abuse Confidence Score: Not applicable
- Blacklist Status: 0 blacklists
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Correlation: None
Historical Observations:
Analysis of 20 historical observations reveals mixed signal types including:
- Network abuse density signals (0.3359)
- Geolocation inference signals with moderate confidence
- Operator routing signals (0.1 score - "Minimal")
- Multiple listing signals with high severity classifications in recent observations
No persistent malicious behavior was detected. Threat observation count shows 1 threat event.
---
NEIGHBORHOOD ANALYSIS
Subnet: 51.195.183.0/24
Total Siblings: 256
Active Siblings: 225
Threat Siblings: 86
Risk Distribution:
- High Risk: 0 IPs
- Medium Risk: 70 IPs
- Low Risk: 30 IPs
Abuse Density: 0.3359 (Mixed classification)
The subnet shows mixed risk characteristics with 86 threat-sibling IPs out of 256 total. Neighbor IPs exhibit risk scores ranging from 25 to 50, with no high-risk neighbors detected.
---
RELATIONSHIP GRAPH
Total Relationships: 68
Primary Relationship Type: Same Network (OVH_282347339) - 63+ relationships
Relationships primarily indicate network-level associations within the OVH infrastructure. No distinct hostname, organization, or certificate relationships were identified beyond the network classification.
---
SECURITY RECOMMENDATIONS
Risk-Based Actions:
- No specific firewall or blocking recommendations generated (risk score below threshold)
- No actionable rules for iptables, nftables, nginx, pfSense, Cloudflare WAF, or AWS WAF
Monitoring Considerations:
- Monitor for service activation on previously closed ports
- Track subnet-level activity given 86 threat-sibling IPs
- Review recent listing signals with high severity classifications
---
INTELLIGENCE CONCLUSION
IP 51.195.183.195 represents legitimate cloud infrastructure for Ahrefs services. Current threat intelligence indicates no active malicious activity. The subnet shows elevated mixed-risk characteristics with 33% abuse density, suggesting monitoring of peer IP addresses is advisable. No immediate blocking or mitigation actions required based on current risk profile.
Status: Monitor / No Action Required
Next Review: Periodic monitoring recommended due to subnet abuse density
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk003-san195.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk003-san195.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 23% | 2 | 2 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-11 21:44:39 UTC |
| Last Seen | 2026-06-27 20:26:51 UTC |
| Profile Built | 2026-06-28 14:31:36 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 27 |
Full dossier details are available via our API.