IPDebrief

51.195.215.160

IP Intelligence Dossier
Your IP: 216.73.217.135
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IPDEBRIEF INTELLIGENCE BRIEFING

Target: 51.195.215.160/32

Classification: Cloud Hosting Infrastructure

Risk Level: Low (Score: 25/100)

Date: 2026-06-25

---

## EXECUTIVE SUMMARY

IP 51.195.215.160 is a low-risk cloud hosting address assigned to Ahrefs Pte Ltd (OVH Infrastructure). The IP serves legitimate infrastructure purposes with no active malicious indicators. However, the parent subnet (51.195.215.0/24) exhibits mixed classification with elevated neighbor activity. SOC analysts should monitor neighborhood context but maintain standard monitoring practices.

---

## OWNERSHIP & INFRASTRUCTURE

---

## THREAT ASSESSMENT

CategoryStatusDetails
Overall RiskLowScore: 25/100
Known AttackerNoNo threat feeds matched
Spam SourceNoNot flagged as spam
Tor Exit NodeNoNot a Tor exit
Proxy/VPNNoNot detected
Blacklist Count0No blacklist entries
DNSBL Listed1/8Minimal operator score (0.2174)
Reputation SourcesNoneNo threat intelligence matches

---

## NEIGHBORHOOD ANALYSIS

Subnet: 51.195.215.0/24

Total Siblings: 256

Active Siblings: 240

Threat Siblings: 113 (44%)

Abuse Density: 0.4414 (Moderate)

Classification: Mixed

Risk Distribution in Subnet:

Context: The target IP shares a subnet with 113 known threat addresses. While the target itself is clean, the neighborhood context suggests this subnet hosts both legitimate and malicious infrastructure. This is common for large hosting providers.

---

## OBSERVATION HISTORY

Signals Observed: 20

Temporal Pattern: Consistent over monitoring period

Ownership Changes: 0 (Stable)

Threat Persistence: 0 days

Last Observed: 2026-06-25 06:55:54 UTC

Recent observations indicate:

No degradation in risk profile observed. Signals remain stable.

---

## RELATIONSHIP GRAPH

Total Relationships: 70

Primary Association: Same Network (OVH_282347345) - 65+ relationships

The IP is primarily linked to its parent network infrastructure. No correlations to known malicious campaigns, certificates, or organizations beyond the hosting provider.

---

## SECURITY ACTIONS

Recommended Actions: None

Firewall Rules: Not required

Rationale: The IP presents a low-risk profile with no active threat indicators. Standard network policies apply. No blocking or filtering recommendations based on current data.

---

## ANALYST NOTES

1. Legitimate Infrastructure: The IP is associated with Ahrefs (SEO analytics platform) and operates as cloud hosting infrastructure.

2. Neighborhood Risk: While the target is clean, 44% of its /24 subnet has been flagged as threats. Monitor for any behavior changes.

3. No Services: Open port scan returned no active services, suggesting this is a backend or infrastructure IP.

4. Stability: Ownership and network classification have remained stable with no recent changes.

---

END OF BRIEFING

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom
RegionENG
CityLondon
TimezoneEurope/London
Latitude51.51
Longitude-0.13

๐Ÿข Ownership & Registration

OrganizationAhrefs Pte Ltd Dmytro
ASNAS16276
Network Nameโ€”
CIDR Blockโ€”
RIRARIN
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRproxy-uk009-san160.ahrefs.net
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-uk009-san160.ahrefs.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
28%
23
routing
13%
11
services
8%
11
ownership
24%
23
reputation
27%
13
geolocation
21%
22
Overall20%913
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-08 11:10:40 UTC
Last Seen2026-06-27 13:19:41 UTC
Profile Built2026-06-28 13:25:39 UTC
Data FreshnessLive
Signal Types20
Total Observations28
๐Ÿ” 20 signal types ยท 28 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.