# IPDEBRIEF INTELLIGENCE BRIEFING
Target IP: 51.195.183.21/32
Classification: Moderate Risk (Score: 40)
Date: 2026-06-15
Intelligence Level: Operational
---
## EXECUTIVE SUMMARY
IP address 51.195.183.21 is a cloud compute infrastructure endpoint operated by Ahrefs Pte Ltd Dmytro under ASN 16276 (OVH). The IP is associated with the ahrefs.net domain and resolved hostname proxy-uk003-san21.ahrefs.net. While the IP itself shows moderate risk, it operates within a high-abuse subnet (51.195.183.0/24) exhibiting significant abuse density.
---
## RISK PROFILE
| Metric | Value | Assessment |
|---|---|---|
| Risk Score | 40 | Moderate Risk |
| Provider Score | 0 | Standard |
| Authority Score | 0 | Standard |
| Operator Score | 0.2174 | Minimal |
| DNSBL Listed | 1 of 8 | Listed |
Infrastructure Classification:
- Type: Cloud Compute (OVH)
- Hosting: Yes
- CDN/Proxy/Tor: No
- Status: Firewalled / No Services Open
---
## GEOLLOCATION & NETWORK POSITION
- Primary Location: London, England, GB (750km accuracy radius)
- BGP Prefix: 51.195.0.0/16
- Origin ASN: 16276 (OVH SAS)
- Geographic Consensus: Inconsistent (signals show both GB and FR)
- Route Stability: Unstable (isRouteStable: false)
- Control Plane: DNSSEC Valid, CAA Records Present
---
## THREAT INDICATORS
- Known Campaigns: None identified
- Attacker Status: Not flagged as known attacker
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0
- Threat Persistence: No persistent malicious activity detected
Note: IP is listed on 1 of 8 DNSBL feeds.
---
## NEIGHBORHOOD CONTEXT (51.195.183.0/24)
- Abuse Density: 0.668 (High Abuse Classification)
- Subnet Size: 256 total IPs
- Active Siblings: 195
- Threat Siblings: 171
- Inherited Risk: 26
- Risk Distribution: 99 medium, 1 low, 0 high
*Context: The /24 subnet shows elevated abuse density, indicating this IP should be evaluated with awareness of neighborhood risk patterns.*
---
## OBSERVATION HISTORY
- Total Signals: 19 observations recorded
- Last Activity: 2026-06-15T04:28:46 UTC
- Recent Signal Types:
- Operator scoring (0.2174 - Minimal)
- DNS resolution (ahrefs.net)
- Geolocation signals (mixed FR/GB)
- Subnet abuse classification (high_abuse)
---
## RELATIONSHIP MAPPING
- Total Relationships: 33
- Primary Association: Same Network (OVH_282347339) - 28+ instances
- Network Type: Cloud infrastructure cluster
---
## RECOMMENDED ACTIONS
Firewall Rules (Block Recommendation)
```bash
# iptables
iptables -A INPUT -s 51.195.183.21 -j DROP
# nftables
nft add rule inet filter input ip saddr 51.195.183.21 drop
# nginx
deny 51.195.183.21;
# Cloudflare WAF
# Block 51.195.183.21 โ IPDebrief risk score 40
# AWS WAF
# Addresses: 51.195.183.21/32
```
SOC Analyst Guidance
1. Block Recommendation: Due to moderate risk score (40) and high-abuse neighborhood context, recommend blocking inbound traffic.
2. Contextual Evaluation: IP belongs to ahosting provider (OVH) with cloud infrastructure. No open ports detected.
3. Monitoring: Monitor for any outbound connections from internal systems to this IP.
4. False Positive Consideration: Ahrefs is a legitimate SEO analytics platform. Verify if traffic is related to authorized services before blocking.
5. Subnet Awareness: Consider broader subnet review (51.195.183.0/24) given 66.8% abuse density.
---
Disclaimer: Intelligence recommendations are probabilistic and should be combined with other signals before taking action. Verify all blocking decisions against organizational policy and business requirements.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk003-san21.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk003-san21.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 25% | 2 | 2 |
| Overall | 20% | 10 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 03:23:24 UTC |
| Last Seen | 2026-06-28 06:33:55 UTC |
| Profile Built | 2026-06-29 00:38:29 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 25 |
Full dossier details are available via our API.