INTELLIGENCE BRIEFING: 51.195.244.158
Classification: Moderate Risk | Date: [Current Date]
Source: IPDebrief Intelligence Platform
---
**Executive Summary**
IP address 51.195.244.158 is a cloud infrastructure endpoint hosted by OVH (ASN 16276) in London, GB. The IP presents a moderate risk profile (score: 40) with no active threat indicators. However, the subnet exhibits high abuse density (0.7608), indicating elevated neighborhood-level risk.
---
**Ownership & Infrastructure**
- Organization: Ahrefs Pte Ltd Dmytro
- ASN: 16276 (OVH)
- Location: London, England, GB
- Infrastructure Type: CloudCompute (Hosting)
- Service Status: Firewalled / No Services
- DNS Resolution: proxy-uk000-san158.ahrefs.net (ahrefs.net)
---
**Threat Assessment**
- Risk Score: 40/100 (Moderate)
- Threat Indicators: None detected
- Known Campaigns: 0
- Blacklist Status: 0 active listings
- DNSBL Count: 1/8 (minimal impact)
- Tor Exit/Proxy: Negative
- Campaign Likelihood: None
Key Observation: No evidence of malicious activity attributed to this specific IP. However, the subnet classification as "high_abuse" warrants neighborhood awareness.
---
**Network Context**
- Subnet: 51.195.244.158/24
- Abuse Density: 0.7608 (High)
- Active Siblings: 203/255
- Threat Siblings: 194
- Inherited Risk: 30/100
Neighbor Analysis: 100 neighboring IPs scanned within /24 subnet. Risk distribution shows 100 medium-risk IPs with no high-risk classifications in immediate neighborhood.
---
**Temporal Analysis**
- Observation Count: 23 historical signals
- Threat Persistence: 0 days (not persistently malicious)
- Ownership Stability: Stable (0 ownership changes)
- Recent Activity: Signals observed June 15-20, 2026 showing consistent moderate-risk classification
---
**Recommendations for SOC**
1. Traffic Monitoring: Monitor outbound connections from 51.195.244.158 to detect potential lateral movement
2. Subnet Awareness: Be cognizant of high abuse density in 51.195.244.0/24 subnet; consider broader subnet-level policies
3. Baseline Traffic: Establish normal traffic patterns given firewalled status
4. No Immediate Block: Current profile does not warrant blocking; maintain monitoring
---
**Indicators for IOC Teams**
- IP: 51.195.244.158
- Associated Domain: ahrefs.net
- Hostname: proxy-uk000-san158.ahrefs.net
- ASN: 16276
---
Analysis Complete. Intelligence derived from IPDebrief platform. No actionable threat indicators detected for this IP at time of analysis.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk000-san158.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk000-san158.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 21:40:46 UTC |
| Last Seen | 2026-06-28 10:13:22 UTC |
| Profile Built | 2026-06-29 04:18:05 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 26 |
Full dossier details are available via our API.