# IP Intelligence Briefing: 51.195.215.81
## Executive Summary
IP address 51.195.215.81 is registered to OVH SAS infrastructure in London, GB. The IP presents a moderate risk profile (risk score 40) within a high-abuse subnet environment. While no active threat indicators were detected, the subnet-level abuse density of 0.7734 warrants monitoring.
## Ownership and Geolocation
- ASN: 16276 (OVH SAS)
- Organization: Ahrefs Pte Ltd Dmytro
- Location: London, England, GB
- Registration: ARIN RIR
- Infrastructure Type: CloudCompute/Hosting
- DNS Hostname: proxy-uk009-san81.ahrefs.net
## Network Classification
The IP operates within OVH cloud infrastructure with the following characteristics:
- Classification: CloudCompute, Hosting
- Services: Firewalled/No Services detected (no open ports)
- Network Role: Not Tor, CDN, VPN, proxy, or mobile carrier
- Route Stability: Unstable (false)
- DNSSEC: Valid
- DNSBL Listings: 1 of 8 total lists
## Neighborhood Analysis
Subnet 51.195.215.0/24 exhibits elevated abuse characteristics:
- Abuse Density: 0.7734 (High Abuse Classification)
- Inherited Risk: 30
- Subnet Statistics: 256 total siblings, 212 active, 198 threat siblings
- Risk Distribution: 98 medium-risk IPs, 2 low-risk IPs, 0 high-risk IPs
## Threat Indicators
Current threat assessment shows:
- No known attacker status
- No spam source classification
- No Tor exit node
- Zero blacklists on profile
- No active campaigns matched
- No correlated IPs identified
## Historical Observations
Analysis of 23 historical observations reveals:
- Recent Classification: High abuse designation (0.7734)
- Geolocation: Consistent GB placement with some coordinate variance (London: 51.5095, -0.0955)
- Threat Persistence: Single threat observation recorded
- Observation Window: Data from 2026-06-14 through 2026-06-18
- Ownership Changes: None recorded
## Related Entities
60 relationships identified, predominantly same-network associations (OVH_282347345). The IP shares network infrastructure with multiple peer addresses in the same /24 block.
## Recommended Actions
Based on the moderate risk profile and high-abuse neighborhood:
1. Monitor rather than blockβrisk score of 40 indicates moderate concern
2. Implement egress filtering if traffic patterns suggest outbound scanning
3. Correlate with other subnet IPs during incident response
4. Update firewall rules to allow legitimate ahrefs.net traffic while restricting other ports
## Intelligence Assessment
This IP represents standard cloud hosting infrastructure with no active malicious indicators. The elevated neighborhood abuse density suggests this subnet hosts a mixture of legitimate services and potentially compromised addresses. SOC teams should monitor for behavioral anomalies rather than applying static blocking based on risk score alone.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | proxy-uk009-san81.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk009-san81.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:26 UTC |
| Last Seen | 2026-06-27 06:42:02 UTC |
| Profile Built | 2026-06-28 00:47:58 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 29 |
Full dossier details are available via our API.