# IP INTELLIGENCE BRIEFING: 51.195.215.117/32
## Executive Summary
IP 51.195.215.117 presents MODERATE RISK with a risk score of 50. The address is hosted on OVH cloud infrastructure in London, GB, operating under the domain ahrefs.net. While the IP itself shows no active threat indicators, its subnet (51.195.215.0/24) is classified as HIGH ABUSE with 80.08% abuse density.
## Ownership & Infrastructure
- Organization: Ahrefs Pte Ltd Dmytro (ASN 16276)
- Provider: OVH (CloudCompute infrastructure)
- Location: London, England, GB
- DNS Hostname: proxy-uk009-san117.ahrefs.net
- Network Block: 51.195.0.0/16 (origin ASN 16276)
## Risk Assessment
| Metric | Value |
|---|---|
| Risk Score | 50 (Moderate) |
| DNSBL Listings | 8 total (2 high severity) |
| Route Stability | Unstable |
| DNSSEC | Valid |
| Open Services | None detected |
## Neighborhood Analysis
The 51.195.215.0/24 subnet demonstrates concerning abuse characteristics:
- Abuse Density: 0.8008 (HIGH ABUSE CLASSIFICATION)
- Total Subnet IPs: 256
- Active Siblings: 239 (93% active)
- Threat Siblings: 205 (86% of active IPs)
- Risk Distribution: 53 medium-risk, 47 low-risk neighbors
## Observations
Signal history shows 17 observations recorded. Most recent activity (2026-06-20) indicates:
- Multiple blacklist listings with high severity
- Subnet abuse density confirmed at 0.8008
- Operator score: 0.2174 (Minimal)
## Network Relationships
- 27 total relationships identified
- Multiple associations with network OVH_282347345
- Consistent DNS associations to proxy-uk009-san117.ahrefs.net
- No certificate or organizational relationship matches
## Threat Indicators
- Not: Tor exit node, known attacker, spam source
- No: Active threat campaigns detected
- No: Known malicious behavior in threat feeds
## Recommended Actions
Based on risk profile and neighborhood context, the following controls are recommended:
```bash
# Firewall Blocking
iptables -A INPUT -s 51.195.215.117 -j DROP
nft add rule inet filter input ip saddr 51.195.215.117 drop
# Application-Level
nginx: deny 51.195.215.117;
Cloudflare WAF: Block 51.195.215.117 โ IPDebrief risk score 50
AWS WAF: Addresses [51.195.215.117/32]
```
## Analyst Notes
While the IP shows no direct threat indicators, the high-abuse subnet classification suggests this address may be part of a compromised cloud hosting infrastructure. The moderate risk score (50) combined with 8 DNSBL listings warrants blocking at perimeter controls. Consider implementing subnet-level filtering (51.195.215.0/24) if organizational policy permits, given the 86% threat sibling rate in the neighborhood.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk009-san117.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk009-san117.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 25% | 2 | 2 |
| Overall | 20% | 10 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 21:40:45 UTC |
| Last Seen | 2026-06-28 10:10:52 UTC |
| Profile Built | 2026-06-29 04:15:50 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 22 |
Full dossier details are available via our API.