# IP INTELLIGENCE BRIEFING
## Target: 51.195.183.59/32
EXECUTIVE SUMMARY
IP 51.195.183.59 is a cloud-hosted address operated by OVH (ASN 16276) with moderate risk profile (40/100). Infrastructure identifies as Ahrefs Pte Ltd Dmytro organization, located in London, England. While the IP itself shows no direct threat indicators, the /24 subnet exhibits high abuse density (0.7695) with 197 threat-sibling IPs among 225 active peers.
RISK ASSESSMENT
| Metric | Value |
|---|---|
| **Risk Score** | 40 (Moderate) |
| **Provider Score** | 0 |
| **Authority Score** | 0 |
| **Abuse Confidence** | Not applicable |
| **Classification** | High Abuse / Cloud Compute |
OWNERSHIP & GEOLOCATION
- Organization: Ahrefs Pte Ltd Dmytro
- ASN: 16276 (OVH SAS)
- Location: London, England, GB
- Timezone: Europe/London
- Geolocation Accuracy: 750km radius (inferred)
NETWORK CHARACTERISTICS
- Infrastructure Type: Cloud Compute (OVH)
- Service Status: Firewalled / No Services Detected
- DNS PTR: proxy-uk003-san59.ahrefs.net
- Forward Resolution: proxy-uk003-san59.ahrefs.net
- Domain: ahrefs.net
- DNSSEC: Valid
- CNAME Records: Yes
THREAT INTELLIGENCE
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0
- DNSBL Listings: 1 of 8 total lists
- Known Campaigns: None detected
NEIGHBORHOOD ANALYSIS (51.195.183.0/24)
- Total Siblings: 256 IPs
- Active Siblings: 225 IPs
- Threat Siblings: 197 IPs (87.6% of active)
- Abuse Density: 0.7695 (High)
- Risk Classification: High Abuse
- Neighbor Risk Distribution: 49 Medium, 51 Low risk
OBSERVATION HISTORY
17 observations recorded with consistent cloud/hosting characteristics. Recent observations confirm:
- Stable ASN and subnet classification
- Persistent high-abuse neighborhood classification
- Consistent geolocation inference for London, GB
- No observed changes in threat profile over monitoring period
RELATIONSHIP GRAPH
38 relationships identified, primarily same-network associations with OVH infrastructure (OVH_282347339). No certificate or organization-level relationships detected beyond the immediate network scope.
RECOMMENDED ACTIONS
Based on risk profile (40/100), blocking is recommended for inbound traffic. Implementation rules provided for iptables, nftables, nginx, pfSense, Cloudflare WAF, and AWS WAF.
SOC RECOMMENDATION
Treat as moderate risk. While the IP resolves to legitimate Ahrefs infrastructure, the subnet exhibits elevated abuse activity. Consider:
1. Allow traffic if positive identification with Ahrefs services
2. Block if no legitimate business requirement
3. Monitor for abuse correlation with neighborhood threat IPs
4. Review firewall rules for subnet-level 51.195.183.0/24 if policy permits
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk003-san59.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk003-san59.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 25% | 2 | 2 |
| Overall | 22% | 10 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 21:40:45 UTC |
| Last Seen | 2026-06-28 10:09:27 UTC |
| Profile Built | 2026-06-29 04:14:38 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 22 |
Full dossier details are available via our API.