# IP Intelligence Briefing: 51.195.183.218
## Executive Summary
IP address 51.195.183.218 is a cloud-based hosting resource operated by Ahrefs Pte Ltd on OVH infrastructure. The IP presents moderate risk (score: 40/100) but resides within a high-abuse subnet (abuse density: 0.7656) containing 196 malicious sibling IPs. Current threat indicators show no active malicious campaigns, but the neighborhood context warrants monitoring.
## Network Ownership & Infrastructure
- Organization: Ahrefs Pte Ltd Dmytro
- ASN: 16276 (OVH)
- Location: London, England, GB
- Infrastructure Type: Cloud Compute / Hosting
- DNS PTR: proxy-uk003-san218.ahrefs.net
- State: Firewalled / No Services Detected
## Risk Assessment
- Overall Risk Score: 40 (Moderate Risk)
- Threat Indicators: None detected
- Blacklist Status: 1 DNSBL listing out of 8 total lists
- Tor Exit: No
- Known Attacker: No
- Spam Source: No
## Subnet Analysis (51.195.183.0/24)
The parent /24 subnet exhibits elevated abuse characteristics:
- Abuse Density: 0.7656 (High Abuse Classification)
- Active Siblings: 225
- Threat Siblings: 196
- Inherited Risk: 30
Neighbor sampling reveals mixed risk distribution: 60 medium-risk neighbors, 40 low-risk neighbors, and 0 high-risk neighbors in the sampled set.
## Historical Observations
Analysis of 21 historical observations indicates:
- Threat Persistence: 0 days (not persistently malicious)
- Ownership Stability: 0 ownership changes detected
- Recent Activity: DNS resolution confirmed to ahrefs.net
- Geolocation: Inferred to GB with 28% confidence (multi-signal inference)
- BGP Prefix: 51.195.0.0/16 (route stability: false)
## Network Relationships
- 45 relationships identified
- Primary Association: Same network relationships to OVH infrastructure (OVH_282347339)
- No certificate or hostname relationships detected in current graph
## Recommended Actions
1. Allow with Monitoring: The IP belongs to Ahrefs (legitimate SEO tools provider), but monitor for anomalies
2. Subnet Awareness: Implement subnet-based filtering for 51.195.183.0/24 due to high abuse density
3. DNSBL Verification: Investigate the single DNSBL listing to determine listing reason
4. Behavioral Analysis: Monitor for unusual traffic patterns from this IP given neighborhood threat context
## Intelligence Conclusion
This IP represents legitimate infrastructure hosted by Ahrefs within a high-abuse OVH subnet. The moderate risk score is contextual to the neighborhood's elevated threat density rather than IP-specific malicious activity. Recommended approach is allow with monitoring, but maintain awareness of the subnet's abuse characteristics.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk003-san218.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk003-san218.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 03:23:24 UTC |
| Last Seen | 2026-06-28 06:34:31 UTC |
| Profile Built | 2026-06-29 00:38:29 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 26 |
Full dossier details are available via our API.