IP Intelligence Briefing: 51.195.183.45
*Generated via IPDebrief Analysis*
---
**Key Threat Indicators**
- Risk Profile: Moderate Risk (Score: 40). No direct malicious indicators (no known campaigns, spam, or abuse).
- Network Role: Cloud compute instance hosted by OVH, classified as "Firewalled / No Services."
- Ownership: Registered to Ahrefs Pte Ltd (ASN 16276), a legitimate Singapore-based company.
- Geolocation: London, England, UK. Plausible geolocation with 500 km distance and 87โ94 ms RTT.
---
**Threat Context**
- Subnet Analysis:
- /24 Subnet: 51.195.183.45/24.
- Abuse Density: 65.62% (high abuse classification).
- Neighbor Risk: 99% of neighbors rated "medium" risk, 1% "low."
- Inherited Risk: 26 points (likely due to subnet-level abuse).
- Historical Observations:
- Stable routing (BGP route stability score: 0.43).
- No recent threats or DNS anomalies detected.
- Geo-validation consistent with London, UK.
---
**Network Relationships**
- Shared Subnet: Linked to OVH network OVH_282347339 (256 IPs in subnet).
- Hosting Environment: Part of a cloud infrastructure with no open services or TLS certificates detected.
- DNS: Resolves to `proxy-uk003-san45.ahrefs.net` (likely internal/managed domain).
---
**Recommendations**
1. Monitor Subnet Activity: High abuse density in the 51.195.183.0/24 subnet suggests potential for lateral movement or compromised hosts.
2. Verify Hosting Configuration: Confirm Ahrefs' security practices for cloud instances, as the IP is part of a hosting environment.
3. Check for Anomalies: Monitor for unexpected outbound traffic or service creation, given the "no services" classification.
4. Subnet-Level Mitigation: Consider rate-limiting or blocking high-risk neighbors in the 51.195.183.0/24 subnet.
---
Note: No immediate action required for this IP itself, but contextual risks from the subnet and hosting provider warrant closer scrutiny.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | 51.195.0.0/16 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk003-san45.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk003-san45.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 4 |
| routing | 17% | 2 | 3 |
| services | 12% | 2 | 2 |
| ownership | 22% | 3 | 4 |
| reputation | 26% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 22% | 12 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:25 UTC |
| Last Seen | 2026-06-27 06:35:41 UTC |
| Profile Built | 2026-06-28 00:42:19 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 32 |
Full dossier details are available via our API.