# IP Intelligence Briefing: 51.195.183.197
## Executive Summary
IP address 51.195.183.197 is a cloud-compute infrastructure node operated by OVH, registered to Ahrefs Pte Ltd (Dmytro). The asset demonstrates moderate risk characteristics (Risk Score: 40) with no open services, but exhibits concerning patterns including DNSBL listings and high-abuse subnet classification. SOC analysts should monitor for potential policy violations rather than immediate threat activity.
## Ownership and Infrastructure
| Attribute | Value |
|---|---|
| **Organization** | Ahrefs Pte Ltd Dmytro |
| **ASN** | 16276 |
| **RIR** | ARIN |
| **Geolocation** | London, England (GB) |
| **Infrastructure Type** | Cloud Compute (OVH) |
| **Network Role** | Hosting Provider |
The IP resolves to hostname `proxy-uk003-san197.ahrefs.net` within the `ahrefs.net` domain. No active services are detected; the node is firewalled with no open ports.
## Threat Assessment
| Indicator | Status |
|---|---|
| **Overall Risk Score** | 40 (Moderate Risk) |
| **DNSBL Listings** | 1 of 8 total lists |
| **Known Attacker** | No |
| **Tor Exit Node** | No |
| **Spam Source** | No |
| **Campaign Correlation** | None detected |
Control plane analysis indicates the IP is listed on 1 DNS blacklist out of 8 total lists reviewed. The abuse confidence score remains uncalculated. No known attack campaigns or threat indicators are associated with this address.
## Neighborhood Analysis
The IP resides in subnet 51.195.183.0/24, which exhibits elevated abuse activity:
- Abuse Density: 58.6%
- Classification: High Abuse
- Inherited Risk Score: 23
- Total Siblings: 256
- Active Siblings: 150
- Threat Siblings: 150
Risk distribution across the subnet shows 99 medium-risk neighbors and 1 low-risk neighbor, with no high-risk neighbors currently flagged.
## Historical Trends
Observation history captures 24 signal instances, with the most recent data (June 2026) showing:
- Abuse density fluctuated between 0.707 and baseline levels
- Classification remained consistently "high_abuse"
- Max DNSBL listing severity: High
- Domain CAA records present with 1 issuer
Temporal analysis indicates 0 ownership changes and 0 threat persistence days, suggesting the IP is not persistently malicious but maintains elevated risk characteristics.
## Recommended Actions
| Action Type | Recommendation |
|---|---|
| **Monitoring** | Add to watchlist due to subnet abuse density |
| **DNSBL** | Review specific blacklist listings for context |
| **Traffic Analysis** | Monitor for unexpected traffic patterns from this node |
| **False Positive Check** | Verify if activity is consistent with Ahrefs operations |
## Intelligence Notes
While the infrastructure is registered to Ahrefsβa legitimate SEO analytics platformβthe IP demonstrates behavioral patterns inconsistent with typical enterprise operations. The high DNSBL listing count and subnet abuse density warrant continued monitoring. No immediate blocking is recommended, but traffic should be logged and reviewed for policy compliance.
---
*Report generated: June 2026*
*Data Source: IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | proxy-uk003-san197.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk003-san197.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 25% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-10 10:13:56 UTC |
| Last Seen | 2026-06-27 17:33:47 UTC |
| Profile Built | 2026-06-28 17:39:23 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 29 |
Full dossier details are available via our API.