# IP Intelligence Briefing: 51.195.215.125/32
Classification: Moderate Risk | Date: Current | Status: Active
## Executive Summary
IP address 51.195.215.125 is a cloud compute infrastructure asset operated by Ahrefs Pte Ltd Dmytro within the OVH hosting environment (ASN 16276). The IP presents a moderate risk profile (score: 40) and is part of a subnet (51.195.215.0/24) exhibiting high abuse density (0.6953). The asset shows persistent DNS presence under the ahrefs.net domain with proxy hostname designation.
## Network Ownership & Infrastructure
- Organization: Ahrefs Pte Ltd Dmytro
- ASN: 16276 (OVH SAS)
- Infrastructure Type: CloudCompute
- Location: London, England, GB (Europe/London)
- Geolocation Confidence: 750km accuracy radius, 5 geo-source consensus
- DNS Resolution: proxy-uk009-san125.ahrefs.net
- Service Status: Firewalled/No Services detected (no open ports, TLS certificates, or HTTP services)
## Risk Assessment
| Metric | Value | Classification |
|---|---|---|
| Overall Risk Score | 40 | Moderate |
| Provider Score | 0 | N/A |
| Authority Score | 0 | N/A |
| Subnet Abuse Density | 0.6953 | High Abuse |
| Inherited Risk | 27 | Moderate |
| Blacklist Count | 0 | Clean |
| DNSBL Listed | 1 of 8 | Partial |
## Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Known Campaigns: None identified
- Threat Feeds: None active
- Abuse Confidence Score: Not computed
## Neighborhood Analysis
The 51.195.215.0/24 subnet contains 256 total addresses with 198 active. Risk distribution across neighbors shows:
- High Risk: 0 IPs
- Medium Risk: 74 IPs
- Low Risk: 26 IPs
- Threat Siblings: 178
Notable neighbor risk scores range from 25-40, with several addresses showing consistent authority scores of 50.
## Temporal Analysis
- Observation Count: 27 signals recorded
- Recent Activity: Multiple observations on 2026-06-27
- Threat Persistence: 0 days
- Ownership Changes: 0
- Operator Score: 0.2174 (Minimal)
Key historical signals include DNS resolution confirmations and operator classification assessments showing consistent minimal operator risk.
## Intelligence Assessment
The IP 51.195.215.125 is part of OVH's cloud infrastructure hosting Ahrefs services. While the individual IP shows no direct malicious indicators, the subnet exhibits elevated abuse density (0.6953) with 178 threat-sibling IPs. The moderate risk classification (40) is primarily driven by neighborhood context rather than direct threat indicators on this specific address.
## Recommended Actions
1. Monitoring: Continue monitoring subnet 51.195.215.0/24 for lateral threat activity
2. Firewall Rules: No immediate blocking recommended; maintain observation
3. Threat Intel: Correlate with Ahrefs known infrastructure to distinguish legitimate vs. compromised assets
4. Baseline: Establish behavioral baseline for proxy hostname activity patterns
---
*Report generated from IPDebrief Intelligence Platform data. All metrics derived from observed signals and historical analysis.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk009-san125.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk009-san125.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 17% | 2 | 3 |
| ownership | 17% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 23% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-12 15:48:20 UTC |
| Last Seen | 2026-06-27 21:47:04 UTC |
| Profile Built | 2026-06-28 21:52:38 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 28 |
Full dossier details are available via our API.