# IP Intelligence Briefing: 51.195.215.52/32
Classification: Moderate Risk (Score: 40/100)
Date: 2026-06-28
---
## Executive Summary
IP address 51.195.215.52 is classified as Moderate Risk with no active malicious indicators. The address is associated with legitimate infrastructure owned by Ahrefs Pte Ltd Dmytro and hosted on OVH cloud infrastructure in London, England. While the IP itself shows no direct threat indicators, the surrounding /24 subnet demonstrates elevated abuse density, warranting contextual monitoring.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **ASN** | 16276 (OVH) |
| **Organization** | Ahrefs Pte Ltd Dmytro |
| **Geolocation** | London, England, GB |
| **Timezone** | Europe/London |
| **Infrastructure Type** | Cloud/Hosting |
| **Service Status** | Firewalled / No Services |
| **DNS** | proxy-uk009-san52.ahrefs.net |
| **Registration RIR** | ARIN |
---
## Threat Indicators Assessment
Active Threats: None detected
- Known Campaigns: 0 matches
- Blacklist Entries: 0
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Abuse Confidence: Not applicable
Control Plane Analysis:
- Operator Score: 0.2174 (Minimal)
- Route Stability: False
- DNSSEC: Valid
- RPKI State: Not evaluated
- IRR Consistency: Not evaluated
---
## Neighborhood Risk Context
The IP resides within subnet 51.195.215.0/24, which presents elevated contextual risk:
- Subnet Abuse Density: 0.8086 (High)
- Classification: high_abuse
- Total Siblings: 256
- Active Siblings: 239
- Threat Siblings: 207
- Inherited Risk Score: 32
Risk Distribution Across Subnet:
- High Risk: 0 IPs
- Medium Risk: 22 IPs
- Low Risk: 78 IPs
The high abuse density indicates significant infrastructure sharing within the /24, suggesting potential collateral risk exposure despite the target IP's clean profile.
---
## Historical Observations
Observation Count: 20 signals recorded
Recent Signal Timeline:
- 2026-06-28 18:52:50 UTC: Cloud infrastructure classification confirmed (OVH, Hosting enabled)
- 2026-06-20 16:46:02 UTC: Geolocation inferred as GB (confidence 0.28)
- 2026-06-20 16:45:38 UTC: Subnet abuse density signal recorded (high_abuse classification)
- 2026-06-20 16:45:17 UTC: Control plane operator score assessed (Minimal)
Temporal Analysis:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Persistently Malicious: No
- Threat Observation Count: 1
The IP demonstrates stable characteristics with no observed threat escalation over the observation period.
---
## Entity Relationships
Total Relationships Identified: 41
Primary Associations:
- Same Network: OVH_282347345 (41 instances)
- All relationships classified as Same Network with no distinct organizational or hostname variations detected
---
## Comparative Analysis
Comparison with 51.195.215.100:
- Same Provider: Yes (OVH)
- Same Organization: Yes (Ahrefs Pte Ltd Dmytro)
- Same Country: Yes (GB)
- Same Subnet: Yes
- Risk Delta: +15 (51.195.215.52 scored 40 vs 25)
- Stability: Both classified as Stable (100% score)
Both IPs share identical ownership and geolocation attributes with similar infrastructure characteristics.
---
## Recommended Actions
Immediate Actions: No blocking or alerting required based on current risk profile.
Contextual Monitoring:
- Monitor subnet 51.195.215.0/24 for abuse activity given 0.8086 abuse density
- Track any DNS resolution changes to ahrefs.net domains
- Monitor for new open ports or service emergence on this IP
Firewall/Security Configuration:
- Default allow or permit based on organizational policy for OVH/ahrefs.net traffic
- No specific iptables/nftables rules recommended
- No WAF rules required (no active services detected)
Threat Intelligence Integration:
- Tag for contextual awareness (shared subnet with high abuse density)
- Include in network baselining for legitimate OVH hosting traffic
- Monitor for any correlation with known Ahrefs-related campaigns
---
## Intelligence Confidence
Overall Confidence: High
- Data sufficiency: All dimensions covered (6/6)
- Source validation: Multi-signal inference confirmed
- Stability: Consistent classification across observation period
Status: MONITOR (No immediate threat action required)
---
*Report generated by IPDebrief Intelligence Platform. Data accurate as of 2026-06-28.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk009-san52.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk009-san52.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 09:13:28 UTC |
| Last Seen | 2026-06-28 18:53:05 UTC |
| Profile Built | 2026-06-29 06:56:26 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.