## INTELLIGENCE BRIEFING: 51.195.244.150/32
Classification: Moderate Risk | Risk Score: 40 | Status: Active Cloud Infrastructure
Ownership and Infrastructure
IP 51.195.244.150 is registered to ASN 16276 (OVH), operating under the organization "Ahrefs Pte Ltd Dmytro." The infrastructure is hosted on OVH cloud compute infrastructure in London, England, GB. DNS resolution identifies the hostname proxy-uk000-san150.ahrefs.net within the ahrefs.net domain. The IP presents no open services, with network classification indicating "Firewalled / No Services."
Geographic and Network Context
Geolocation data places the IP in London, GB, with an accuracy radius of 750 km. The subnet 51.195.244.0/24 exhibits critical risk characteristics:
- Abuse Density: 0.8047 (High Abuse)
- Active Siblings: 226 of 256 total
- Threat Siblings: 206 classified as threats
- Inherited Risk: 32
This indicates the IP belongs to a high-abuse-density subnet with approximately 91% of active neighbors showing threat indicators.
Threat Assessment
Direct threat indicators for this specific IP are absent:
- Blacklist Count: 0
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
However, the neighborhood context presents elevated concern. The subnet's high abuse density and threat sibling concentration suggest potential infrastructure compromise or policy violations within the shared hosting environment.
Behavioral History
Historical analysis across 23 observations indicates consistent high abuse classification for the subnet. Recent observations (June 18, 2026) confirm sustained threat activity within the 51.195.244.0/24 space. Geographic validation remains plausible with minimum RTT of 84ms and average RTT of 87.6ms.
Recommended Actions
Based on the risk profile and neighborhood context, the following defensive measures are recommended:
Block at Network Perimeter:
```bash
iptables -A INPUT -s 51.195.244.150 -j DROP
nft add rule inet filter input ip saddr 51.195.244.150 drop
nginx: deny 51.195.244.150;
```
Application-Level Blocking:
- pfSense: Configure 51.195.244.150/32 rule
- Cloudflare WAF: Block IP 51.195.244.150 (Risk score 40)
- AWS WAF: Add 51.195.244.150/32 to block list
Intelligence Summary
This IP represents moderate-risk cloud infrastructure hosted in a high-abuse-density subnet. While the specific IP lacks direct threat indicators, the surrounding network environment shows 206 threat siblings. SOC analysts should consider blocking the IP at network boundaries and monitor for any service activity that may emerge. The subnet's abuse density warrants broader investigation into 51.195.244.0/24 for coordinated malicious activity patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk000-san150.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk000-san150.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:26 UTC |
| Last Seen | 2026-06-27 06:43:42 UTC |
| Profile Built | 2026-06-28 00:50:17 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 28 |
Full dossier details are available via our API.