IP INTELLIGENCE BRIEFING: 51.89.129.12/32
Executive Summary
IP address 51.89.129.12 is a moderate-risk (score: 40) cloud infrastructure endpoint operated by OVH (ASN 16276) for Ahrefs Pte Ltd. The IP resides in London, GB, within an OVH cloud compute environment with no active services exposed. While the specific endpoint shows no direct threat indicators, the /24 subnet exhibits high abuse density (0.625) with 160 threat siblings among 256 total addresses.
Infrastructure Profile
- Ownership: OVH SAS (ASN 16276) / Ahrefs Pte Ltd Dmytro
- Classification: CloudCompute infrastructure (OVH)
- Geolocation: London, England, GB (750km accuracy radius)
- DNS Resolution: proxy-uk008-san12.ahrefs.net โ ahrefs.net
- Services: No open ports detected (firewalled/no services)
- TLS/HTTP: No certificates, no HTTP services
Risk Assessment
- Overall Risk Score: 40/100 (Moderate Risk)
- DNSBL Status: Listed on 1 of 8 total DNSBLs
- Operator Score: 0.2174 (Minimal)
- Abuse Confidence: Not available
- Campaign Correlation: None detected
- Blacklist Count: 0
Network Context (Subnet: 51.89.129.0/24)
- Abuse Density: 0.625 (High abuse classification)
- Inherited Risk: 25/100
- Subnet Statistics: 256 total siblings, 154 active siblings, 160 threat siblings
- Neighbor Risk Distribution: 0 high, 97 medium, 3 low (sample of 100)
- Route Stability: False (route changes detected in 30-day window)
Observation History
- Total Observations: 23 signals recorded
- Recent Signals (June 14, 2026):
- Subnet abuse density: 0.625 (high_abuse classification)
- DNS resolution: ahrefs.net with CAA records present
- Geolocation: GB with 28% confidence
- Operator score: 0.2174 (Minimal)
- Threat Persistence: 0 days (not persistently malicious)
Relationship Graph
- Total Relationships: 62
- Network Associations: Multiple entries linking to OVH_282347344
- Shared Infrastructure: Cloud provider network relationships
Threat Indicators
- No known attacker flags
- No known campaigns correlated
- No Tor exit node activity
- No spam source classification
- No threat feeds triggered
Recommended Actions
- Monitor subnet-level abuse patterns (high abuse density context)
- Evaluate traffic patterns against known Ahrefs infrastructure baselines
- No immediate blocking required (no direct threat indicators)
- Consider geo-blocking if traffic pattern inconsistent with legitimate business needs
Conclusion
The IP represents legitimate cloud hosting infrastructure for a legitimate SEO analytics provider (Ahrefs) within a high-abuse-density OVH subnet. While the subnet context warrants monitoring, the specific IP shows no direct malicious activity. SOC teams should evaluate traffic legitimacy based on established Ahrefs network patterns rather than IP-level blocking.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk008-san12.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk008-san12.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-08 17:18:09 UTC |
| Last Seen | 2026-06-27 14:01:45 UTC |
| Profile Built | 2026-06-28 08:07:01 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 28 |
Full dossier details are available via our API.