# IP INTELLIGENCE BRIEFING: 51.195.183.42/32
## EXECUTIVE SUMMARY
IP 51.195.183.42 is a moderate-risk cloud infrastructure address operated by OVH in London, England. The IP resolves to ahosted domain (ahrefs.net) but presents no open services and operates within a high-abuse density subnet. While not directly associated with active malicious campaigns, the subnet environment warrants defensive monitoring.
## NETWORK PROPERTIES
| Attribute | Value |
|---|---|
| Risk Score | 40 (Moderate Risk) |
| ASN | 16276 (OVH) |
| Organization | Ahrefs Pte Ltd Dmytro |
| Country | GB (United Kingdom) |
| City | London, England |
| Infrastructure Type | CloudCompute |
| Hosting Provider | OVH |
| DNS PTR | proxy-uk003-san42.ahrefs.net |
| Forward Resolution | ahrefs.net |
## THREAT ASSESSMENT
Current Risk Profile: The IP presents moderate risk with a score of 40. No direct threat indicators were observed:
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0
- Active Threat Indicators: None
Subnet Context: The IP operates within subnet 51.195.183.0/24, which exhibits high abuse density (0.707). The subnet contains 256 total sibling IPs with 208 active and 181 classified as threat siblings. This contextual risk factor significantly elevates the operational risk despite the IP's clean direct profile.
## OBSERVATION HISTORY
28 historical observations recorded through June 18, 2026. Recent signals indicate:
- Geolocation validation: Consistent London coordinates with 750km accuracy radius
- Network abuse classification: High abuse subnet designation
- Routing stability: Route stable with zero BGP changes over 30 days
- Operator score: 0.4348 (Basic)
- DNSSEC: Valid
- RPKI: Consistent
## NETWORK RELATIONSHIPS
The IP maintains relationships within the OVH_282347339 network block. The subnet shows extensive interconnectivity with 45+ related network entities, indicating a large-scale cloud infrastructure deployment.
## SERVICES & PORTS
No active services detected on the IP:
- Open Ports: None
- TLS Certificates: None
- HTTP Banner: None
- Connection State: Firewalled / No Services
## RECOMMENDED SECURITY ACTIONS
Immediate Recommendations:
- Firewall Blocking: Consider blocking at perimeter firewall given high-abuse subnet context
- iptables: `iptables -A INPUT -s 51.195.183.42 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 51.195.183.42 drop`
- nginx: `deny 51.195.183.42;`
- pfSense: Add 51.195.183.42/32 to block list
- Cloudflare WAF: Configure block rule with expression `ip.src eq 51.195.183.42`
- AWS WAF: Add IP set with address 51.195.183.42/32
Operational Notes:
- The subnet's high abuse density (0.707) suggests correlation-based blocking may be warranted despite clean direct indicators
- Monitor for any service activation on this IP
- Consider subnet-level blocking if traffic patterns indicate abuse correlation
- The moderate risk score combined with subnet abuse density suggests a "monitor and block" approach rather than immediate investigation
Priority Level: MEDIUM
Action Window: Immediate to 30 days
Monitoring Required: Yes โ track service activation and subnet behavior
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | 51.195.0.0/16 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk003-san42.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk003-san42.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 20% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 24% | 3 | 4 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 24% | 12 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:25 UTC |
| Last Seen | 2026-06-27 06:35:31 UTC |
| Profile Built | 2026-06-28 00:42:19 UTC |
| Data Freshness | Live |
| Signal Types | 28 |
| Total Observations | 33 |
Full dossier details are available via our API.