INTELLIGENCE BRIEFING: 51.195.215.200
Executive Summary
IP 51.195.215.200 is a cloud computing host operated by Ahrefs Pte Ltd Dmytro (AS16276, OVH) with a moderate risk score of 40. The IP resolves to proxy-uk009-san200.ahrefs.net and is associated with the ahrefs.net domain infrastructure. The IP exhibits high-abuse characteristics within its /24 subnet, with 203 threat siblings identified among 238 active peers.
Technical Profile
- Ownership: Ahrefs Pte Ltd Dmytro, AS16276 (OVH)
- Geolocation: England, London, GB (750km accuracy radius)
- Infrastructure: CloudCompute hosting environment
- DNS: proxy-uk009-san200.ahrefs.net (forward confirmed)
- Services: No open ports detected; firewalled/no services
- Network Role: Hosting/Cloud infrastructure
Threat Indicators
- Risk Score: 40 (Moderate Risk)
- Blacklist Status: 0 confirmed blacklists; 1 DNSBL listing detected (max severity: high)
- Abuse Confidence: Not explicitly scored; operator score 0.2174 (Minimal)
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
Temporal Analysis
Historical data shows 23 observations with the following patterns:
- Recent subnet abuse classification signals (June 2026) indicating high-abuse density (0.793) within the 51.195.215.0/24
- DNS signals confirm ahrefs.net domain resolution
- One blacklisting signal with 8 total lists checked, 1 listed
Neighborhood Context
Subnet 51.195.215.0/24 analysis reveals:
- Abuse Density: 0.793 (classified as high_abuse)
- Total Active Siblings: 238
- Threat Siblings: 203
- Risk Distribution: 59 medium-risk, 41 low-risk, 0 high-risk neighbors
Relationships
40 relationships identified, primarily Same Network associations with OVH_282347345 network identifier.
Recommended Actions
The following firewall rules are recommended based on the IP's risk profile:
```
# iptables
iptables -A INPUT -s 51.195.215.200 -j DROP
# nftables
nft add rule inet filter input ip saddr 51.195.215.200 drop
# nginx
deny 51.195.215.200;
# pfSense
51.195.215.200/32
# Cloudflare WAF
{"description":"Block 51.195.215.200 โ IPDebrief risk score 40","action":"block"}
# AWS WAF
{"Addresses":["51.195.215.200/32"],"Description":"IPDebrief risk 40"}
```
Assessment
This IP represents moderate-risk cloud hosting infrastructure. While the IP itself shows no direct malicious indicators (no open services, no known campaigns), its high-abuse neighborhood context warrants defensive blocking. The subnet's elevated abuse density (0.793) and 203 threat siblings suggest this /24 is being used for potentially abusive activities. Recommend blocking at perimeter defenses while monitoring for legitimate traffic patterns from the ahrefs.net domain infrastructure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk009-san200.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk009-san200.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 30% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 09:25:02 UTC |
| Last Seen | 2026-06-28 07:13:38 UTC |
| Profile Built | 2026-06-29 07:19:24 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 26 |
Full dossier details are available via our API.