INTELLIGENCE BRIEFING: 51.195.244.255/32
Classification: MODERATE RISK | Generated: Current | Status: ACTIVE
---
**EXECUTIVE SUMMARY**
IP 51.195.244.255 is a cloud-hosted infrastructure endpoint operated by Ahrefs Pte Ltd Dmytro (ASN 16276, OVH). The IP exhibits moderate risk (score: 40) with minimal direct threat indicators, though it resides in a high-abuse density subnet (51.195.244.0/24) with 83.14% abuse classification and 212 of 255 sibling IPs flagged as threat sources.
---
**OWNERSHIP & INFRASTRUCTURE**
- Organization: Ahrefs Pte Ltd Dmytro
- ASN: 16276 (OVH SAS)
- Location: London, England, GB (verified)
- Infrastructure Type: Cloud Compute / Hosting
- Network Role: Firewalled / No Services Detected
- DNS Record: proxy-uk000-san255.ahrefs.net (ahrefs.net)
- Control Plane: BGP prefix 51.195.0.0/16, route stability: false
- DNSBL Status: Listed on 1 of 8 evaluated blacklists
---
**THREAT INDICATORS**
- Reputation: Moderate Risk (Score: 40)
- Abuse Confidence: Not calculated
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Known Campaigns: None identified
- Direct Threat Indicators: None
- Scan Activity: No open ports or active services detected
---
**SUBNET CONTEXT (51.195.244.0/24)**
- Abuse Density: 0.8314 (High)
- Active Siblings: 207 / 255
- Threat Siblings: 212
- Risk Inheritance: 33
- Neighbor Risk Distribution: 100 medium-risk IPs, 0 high/low
---
**OBSERVATION HISTORY**
- Recent Activity: Signals observed June 15-20, 2026
- Geolocation Consistency: Stable (London, GB)
- Operator Score: 0.2174 (Minimal)
- RTT Profile: 90-99ms average, 473.7km distance from probe location
- Persistence: 1 threat observation recorded
- Ownership Changes: None
---
**RELATIONSHIP GRAPH**
- Total Relationships: 34 entities
- Network Associations: OVH_282347336 (multiple references)
- No Direct Campaign Correlations
---
**RECOMMENDED ACTIONS**
Blocklist Recommendation: Due to moderate risk score and high-abuse subnet context, blocking is recommended.
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 51.195.244.255 -j DROP
# nftables
nft add rule inet filter input ip saddr 51.195.244.255 drop
```
WAF Integration:
- Cloudflare: `ip.src eq 51.195.244.255` โ Block
- AWS WAF: `Addresses: ["51.195.244.255/32"]` โ Block
- Nginx: `deny 51.195.244.255;`
---
**ANALYST NOTES**
This IP shows minimal direct malicious indicators but operates within a high-abuse OVH subnet. The Ahrefs domain association suggests legitimate business use, but the subnet context warrants defensive blocking. Monitor for service activation (port scans detected in historical data). Consider subnet-level monitoring for 51.195.244.0/24 due to 83.14% abuse density.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk000-san255.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk000-san255.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 03:10:14 UTC |
| Last Seen | 2026-06-28 17:47:56 UTC |
| Profile Built | 2026-06-29 05:50:42 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.