IP Intelligence Briefing: 51.195.215.30
Date: 2026-06-08
---
**1. Core Profile**
- Risk Score: Low (25/100)
- Ownership: Registered to Ahrefs Pte Ltd (ASN 16276, OVH provider).
- Geolocation: London, UK (ENG region).
- Network Role: Cloud compute instance (OVH infrastructure).
- Threat Indicators: No malicious activity detected (no abuse confidence, blacklist, or campaign ties).
- DNS: Resolves to `proxy-uk009-san30.ahrefs.net` (Ahrefs subdomain).
---
**2. Observation History**
- Risk Trends: Minimal risk over the past 30 days, with stable scores.
- Key Signals:
- DNSSEC and CAA validation active.
- Subnet abuse density: 0.49 (moderate risk in the 51.195.215.0/24 subnet).
- Traceroute shows plausible UK geolocation (473 km from probe, 90ms avg RTT).
- No Recent Anomalies: No spikes in threat indicators or network instability.
---
**3. Network Relationships**
- Linked Entities:
- OVH Network (ASN 16276): Same provider as 51.195.215.30.
- Ahrefs Subdomain: DNS association with `proxy-uk009-san30.ahrefs.net`.
- Subnet Context:
- 51.195.215.0/24 contains 255 IPs; 128 are active, 126 flagged as risky.
- Abuse Density: 49.41% (mixed classification: 19 inherited risk, 126 threat siblings).
---
**4. Neighborhood Analysis**
- Neighbor Risk Distribution:
- Low Risk: 42 IPs (avg score: 25).
- Medium Risk: 58 IPs (avg score: 50).
- High Risk: 0 IPs.
- Notable Neighbors:
- 51.195.215.0β4: Mixed risk scores (25β50).
- Subnet includes 100+ IPs, with 58% showing medium risk.
---
**5. Recommendations**
- Monitor Subnet: The 51.195.215.0/24 subnet has moderate abuse density; investigate risky neighbors for potential lateral movement.
- Verify Ahrefs Activity: Confirm legitimacy of `proxy-uk009-san30.ahrefs.net` and ensure no unexpected services are exposed.
- Firewall Rules: Block high-risk neighbors in the subnet if they are not part of the organizationβs infrastructure.
- Geolocation Validation: Ensure traffic to this IP aligns with expected UK-based activity.
---
Conclusion:
51.195.215.30 is a low-risk IP associated with Ahrefs, but its subnet contains a significant number of medium-risk neighbors. SOC teams should prioritize monitoring the broader network for potential threats while verifying the legitimacy of the associated domain.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | proxy-uk009-san30.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk009-san30.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 25% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-18 03:23:25 UTC |
| Last Seen | 2026-06-28 06:38:08 UTC |
| Profile Built | 2026-06-29 00:43:09 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 27 |
Full dossier details are available via our API.