IP INTELLIGENCE BRIEFING: 51.195.183.217
OVERVIEW
IP address 51.195.183.217 is hosted by OVH (ASN 16276) within the Ahrefs Pte Ltd network block (51.195.0.0/16). The IP is located in London, England, GB. Current risk assessment: Moderate Risk (Score: 50/100).
NETWORK CLASSIFICATION
- Provider: OVH (cloud/hosting infrastructure)
- Infrastructure Type: Hosting
- Service Status: Firewalled / No Services (no open ports detected)
- DNS Resolution: proxy-uk003-san217.ahrefs.net (ahrefs.net)
- BGP Prefix: 51.195.0.0/16
- Route Stability: False
THREAT INDICATORS
- DNSBL Listed: 2 of 8 blacklist feeds
- Abuse Confidence Score: Not applicable
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Proxy: No
- Campaign Activity: None identified
SUBNET ABUSE CONTEXT
The /24 subnet (51.195.183.0.0/24) shows elevated abuse characteristics:
- Abuse Density: 71.48%
- Classification: High Abuse
- Threat Siblings: 183 of 256 total IPs in subnet
- Inherited Risk Score: 28
Neighbor analysis of 100 sampled IPs in the subnet shows a risk distribution of 0 high-risk, 71 medium-risk, and 29 low-risk addresses.
OBSERVATION HISTORY
Analysis of 20 historical observations indicates:
- Consistent ownership (no changes detected)
- No persistent malicious behavior
- Recent operator score: 0.1 (Minimal)
- Subnet abuse density has remained stable at 0.7148 since June 19
RELATIONSHIP GRAPH
56 relationships identified, primarily same-network associations with OVH_282347339. No certificate or hostname relationships beyond the ahrefs.net domain.
RECOMMENDED ACTIONS
The following firewall rules are recommended for immediate implementation:
iptables:
```
iptables -A INPUT -s 51.195.183.217 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 51.195.183.217 drop
```
nginx:
```
deny 51.195.183.217;
```
Cloudflare WAF:
```json
{"description":"Block 51.195.183.217 โ IPDebrief risk score 50","action":"block","filter":{"expression":"ip.src eq 51.195.183.217"}}
```
AWS WAF:
```json
{"Addresses":["51.195.183.217/32"],"Description":"IPDebrief risk 50"}
```
ANALYST NOTES
This IP belongs to a hosting infrastructure with elevated subnet-level abuse. While the IP shows no direct malicious indicators, its association with 183 threat-sibling IPs in the same /24 subnet warrants blocking. The DNSBL listings indicate some level of reputation degradation. Monitor for any service activation on this IP.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk003-san217.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk003-san217.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-11 21:11:19 UTC |
| Last Seen | 2026-06-27 20:08:58 UTC |
| Profile Built | 2026-06-28 14:13:09 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 27 |
Full dossier details are available via our API.