IPDebrief

51.195.183.197

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 51.195.183.197

## Executive Summary

IP address 51.195.183.197 is a cloud-compute infrastructure node operated by OVH, registered to Ahrefs Pte Ltd (Dmytro). The asset demonstrates moderate risk characteristics (Risk Score: 40) with no open services, but exhibits concerning patterns including DNSBL listings and high-abuse subnet classification. SOC analysts should monitor for potential policy violations rather than immediate threat activity.

## Ownership and Infrastructure

AttributeValue
**Organization**Ahrefs Pte Ltd Dmytro
**ASN**16276
**RIR**ARIN
**Geolocation**London, England (GB)
**Infrastructure Type**Cloud Compute (OVH)
**Network Role**Hosting Provider

The IP resolves to hostname `proxy-uk003-san197.ahrefs.net` within the `ahrefs.net` domain. No active services are detected; the node is firewalled with no open ports.

## Threat Assessment

IndicatorStatus
**Overall Risk Score**40 (Moderate Risk)
**DNSBL Listings**1 of 8 total lists
**Known Attacker**No
**Tor Exit Node**No
**Spam Source**No
**Campaign Correlation**None detected

Control plane analysis indicates the IP is listed on 1 DNS blacklist out of 8 total lists reviewed. The abuse confidence score remains uncalculated. No known attack campaigns or threat indicators are associated with this address.

## Neighborhood Analysis

The IP resides in subnet 51.195.183.0/24, which exhibits elevated abuse activity:

Risk distribution across the subnet shows 99 medium-risk neighbors and 1 low-risk neighbor, with no high-risk neighbors currently flagged.

## Historical Trends

Observation history captures 24 signal instances, with the most recent data (June 2026) showing:

Temporal analysis indicates 0 ownership changes and 0 threat persistence days, suggesting the IP is not persistently malicious but maintains elevated risk characteristics.

## Recommended Actions

Action TypeRecommendation
**Monitoring**Add to watchlist due to subnet abuse density
**DNSBL**Review specific blacklist listings for context
**Traffic Analysis**Monitor for unexpected traffic patterns from this node
**False Positive Check**Verify if activity is consistent with Ahrefs operations

## Intelligence Notes

While the infrastructure is registered to Ahrefsβ€”a legitimate SEO analytics platformβ€”the IP demonstrates behavioral patterns inconsistent with typical enterprise operations. The high DNSBL listing count and subnet abuse density warrant continued monitoring. No immediate blocking is recommended, but traffic should be logged and reviewed for policy compliance.

---

*Report generated: June 2026*

*Data Source: IPDebrief Intelligence Platform*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡¬πŸ‡§ United Kingdom
RegionEngland
CityLondon
TimezoneEurope/London
Latitude48.86
Longitude2.34

🏒 Ownership & Registration

OrganizationAhrefs Pte Ltd Dmytro
ASNAS16276
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRproxy-uk003-san197.ahrefs.net
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-uk003-san197.ahrefs.net

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
35%
24
routing
13%
11
services
15%
22
ownership
20%
23
reputation
28%
13
geolocation
35%
23
Overall25%1016
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-10 10:13:56 UTC
Last Seen2026-06-27 17:33:47 UTC
Profile Built2026-06-28 17:39:23 UTC
Data FreshnessLive
Signal Types22
Total Observations29
πŸ” 22 signal types Β· 29 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.