# IP INTELLIGENCE BRIEFING: 51.195.244.114/32
Classification: Moderate Risk | Provider: OVH | Location: London, England, United Kingdom
---
## PROFILE SUMMARY
| Attribute | Value |
|---|---|
| **Risk Score** | 50/100 (Moderate) |
| **ASN** | 16276 (OVH) |
| **Organization** | Ahrefs Pte Ltd Dmytro |
| **Network Classification** | Hosting Provider |
| **DNS** | proxy-uk000-san114.ahrefs.net |
| **Status** | Firewalled / No Active Services |
| **Country** | GB (United Kingdom) |
---
## THREAT INDICATORS
- DNSBL Listings: 2 of 8 total lists (listed count indicates active blacklisting)
- Abuse Density: 0.8314 (High-abuse subnet classification)
- Threat Persistence: 0 days (no persistent malicious behavior observed)
- Known Campaigns: None identified
- Tor/Proxy/VPN: Not detected
---
## NETWORK CONTEXT
Subnet Analysis: 51.195.244.0/24
- Total Siblings: 255
- Active Siblings: 207
- Threat Siblings: 212
- Inherited Risk: 33
- Subnet Classification: High Abuse
The subnet exhibits elevated threat density with approximately 83% of active addresses classified as threats. This is consistent with the IP's hosting infrastructure designation.
---
## OBSERVATION HISTORY
- Total Observations: 22 signals over monitoring period
- Latest Activity: 2026-06-28
- Listings: 8 blacklist sources (max severity: High)
- Behavioral Pattern: No persistent malicious activity detected
- Provider Consistency: OVH hosting infrastructure (confirmed across multiple observations)
---
## INFRASTRUCTURE RELATIONSHIPS
- Primary Network: OVH_282347336 (43 relationships identified)
- Associated Hostnames: proxy-uk000-san114.ahrefs.net
- Certificate Records: 0 (no SSL/TLS certificates observed)
---
## RECOMMENDED ACTIONS
Status: Probabilistic recommendations for defensive filtering
| System | Action |
|---|---|
| iptables | `iptables -A INPUT -s 51.195.244.114 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 51.195.244.114 drop` |
| nginx | `deny 51.195.244.114;` |
| pfSense | `51.195.244.114/32` |
| Cloudflare WAF | Block with expression: `ip.src eq 51.195.244.114` |
| AWS WAF | Add to blocked addresses: `51.195.244.114/32` |
Implementation Note: These recommendations are based on risk scoring algorithms and should be combined with other contextual signals before enforcement. Consider whitelist validation for legitimate traffic patterns.
---
Assessment: This IP address is associated with OVH hosting infrastructure in London, United Kingdom. While the individual risk score is moderate (50), the subnet exhibits high abuse density. The IP has no active services and no persistent malicious behavior detected. Blacklist listings from 8 sources suggest prior abuse activity. Recommend blocking with awareness of potential false positives from shared hosting infrastructure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk000-san114.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk000-san114.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 39% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 25% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 21:00:54 UTC |
| Last Seen | 2026-06-28 16:18:39 UTC |
| Profile Built | 2026-06-29 04:22:34 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.