# IP INTELLIGENCE BRIEFING: 51.195.215.12/32
Classification: Moderate Risk / Cloud Infrastructure
Date: 2026-06-15
Analyst: IPDebrief Intelligence Unit
---
## EXECUTIVE SUMMARY
IP 51.195.215.12 is a cloud compute infrastructure address operated by OVH (ASN: 16276) within the United Kingdom. The IP presents a moderate risk profile (Score: 40) with no active malicious indicators. The address is associated with Ahrefs Pte Ltd and resolves to proxy-uk009-san12.ahrefs.net. While the IP itself shows no direct threat indicators, the /24 subnet exhibits elevated abuse density (0.7617), suggesting contextual risk from neighboring addresses.
---
## CORE PROFILE
| Attribute | Value |
|---|---|
| **Risk Score** | 40 (Moderate Risk) |
| **ASN** | 16276 (OVH) |
| **Organization** | Ahrefs Pte Ltd Dmytro |
| **Country** | GB (London) |
| **Infrastructure** | CloudCompute / Hosting |
| **DNS** | proxy-uk009-san12.ahrefs.net |
| **Hosted Domain** | ahrefs.net |
| **Status** | Firewalled / No Services |
---
## THREAT ASSESSMENT
Direct Indicators:
- No known malicious campaigns detected
- No active threat feeds matches
- Zero blacklist entries (abuseConfidenceScore: null)
- Not identified as Tor exit node, spam source, or known attacker
- No open ports or active services exposed
Contextual Risk:
- /24 subnet classified as "high_abuse" with abuse density of 0.7617
- Subnet contains 256 total siblings; 199 active, 195 threat siblings
- Control plane shows unstable routing (isRouteStable: false)
- Listed on 1 of 8 DNSBL checks
---
## OBSERVATION HISTORY
Analysis Period: 19 total observations
Recent Activity: 2026-06-15
Temporal analysis indicates stable ownership patterns with no malicious activity persistence. Historical operator scoring remains consistent at 0.2174. Geolocation confidence varies (0.28โ0.60) across observation periods. No significant escalation in threat signals observed.
---
## NETWORK RELATIONSHIPS
- 34 relationships identified
- Network Associations: Multiple connections to OVH_282347345 (same network block)
- No certificate or hostname correlations beyond primary DNS records
- No correlated IPs across campaigns or threat intelligence feeds
---
## NEIGHBORHOOD ANALYSIS
Subnet: 51.195.215.0/24
| Metric | Value |
|---|---|
| Abuse Density | 0.7617 |
| Classification | high_abuse |
| Active Siblings | 199 / 256 |
| Threat Siblings | 195 / 256 |
Sample Neighbor Risk Scores:
- 51.195.215.0: Risk 40 / Authority 50
- 51.195.215.1: Risk 40 / Authority 50
- 51.195.215.2: Risk 40 / Authority 50
The subnet exhibits widespread medium-risk characteristics with concentrated threat activity.
---
## RECOMMENDED ACTIONS
Detection & Monitoring:
1. Monitor for DNS queries to ahrefs.net from unexpected sources
2. Flag outbound traffic to proxy-uk009-san12.ahrefs.net for review
3. Implement subnet-level awareness for 51.195.215.0/24 due to high abuse density
Blocking Decision:
- Block: No (IP shows no direct malicious indicators)
- Monitor: Yes (contextual subnet risk warrants observation)
- Allow: Yes (legitimate cloud infrastructure for Ahrefs services)
Firewall Rules:
- No immediate blocking required
- Consider rate limiting for connections to this IP if part of broader subnet monitoring
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk009-san12.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk009-san12.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 21:00:53 UTC |
| Last Seen | 2026-06-28 16:15:48 UTC |
| Profile Built | 2026-06-29 10:20:59 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.