IPDebrief

51.89.129.163

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target IP: 51.89.129.163/32

Date: 2026-06-19

Classification: Moderate Risk (Score: 40/100)

---

## EXECUTIVE SUMMARY

IP address 51.89.129.163 is a cloud compute endpoint operated by OVH (ASN 16276) in London, England, registered to Ahrefs Pte Ltd. The IP resolves to proxy-uk008-san163.ahrefs.net and presents moderate risk (40/100). While no active threat indicators or known attack campaigns are associated with this specific address, the IP resides within a high-abuse density subnet (51.89.129.0/24) where 70% of sibling IPs exhibit medium risk and 30% exhibit low risk.

---

## OWNERSHIP & GEOLOCATION

---

## NETWORK ENVIRONMENT ANALYSIS

The IP is embedded in subnet 51.89.129.0/24 with the following characteristics:

MetricValue
Subnet Abuse Density0.707 (High Abuse)
Total Sibling IPs256
Active Siblings194
Threat-Associated Siblings181
Inherited Risk Score28/100

Risk Distribution in /24: 70% medium risk, 30% low risk, 0% high risk (sample of 100 neighbors analyzed).

The high abuse density indicates this subnet contains significant malicious activity, though the target IP itself shows no active threat indicators.

---

## THREAT INTELLIGENCE

Current Threat Status:

Control Plane Data:

---

## OBSERVATION HISTORY

Recent signals (June 2026) indicate:

No persistent malicious behavior detected. Ownership changes: 0. Threat persistence: 0 days.

---

## INFRASTRUCTURE RELATIONSHIPS

The IP maintains 53 documented relationships, primarily with network infrastructure entities (OVH_282347344). No connections to known malicious campaigns, certificates, or related threat actors identified.

---

## RECOMMENDED ACTIONS

Based on risk profile and neighborhood analysis, the following firewall rules are recommended:

```bash

# iptables

iptables -A INPUT -s 51.89.129.163 -j DROP

# nftables

nft add rule inet filter input ip saddr 51.89.129.163 drop

# pfSense

51.89.129.163/32

```

Platform-Specific Rules:

---

## ANALYST NOTES

1. Context: While the IP itself shows no active threat indicators, the parent subnet exhibits high abuse density. Consider blocking the entire /24 if acceptable for your threat model.

2. Legitimate Use: The IP resolves to a legitimate ahrefs.net domain, suggesting potential legitimate use. However, the high abuse neighborhood warrants caution.

3. Recommendation: Implement rate limiting or connection throttling as an intermediate measure before full blocking. Monitor for any changes in behavior from this IP or adjacent addresses in the /24 subnet.

4. Related Subnet: Consider analyzing adjacent subnets (51.89.128.0/24, 51.89.130.0/24) for additional threat intelligence.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom
RegionEngland
CityLondon
TimezoneEurope/London
Latitude51.51
Longitude-0.13

๐Ÿข Ownership & Registration

OrganizationAhrefs Pte Ltd Dmytro
ASNAS16276
Network Nameโ€”
CIDR Blockโ€”
RIRARIN
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRproxy-uk008-san163.ahrefs.net
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-uk008-san163.ahrefs.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
33%
23
routing
13%
11
services
21%
22
ownership
24%
23
reputation
31%
13
geolocation
33%
23
Overall26%1015
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-13 06:38:43 UTC
Last Seen2026-06-27 22:57:10 UTC
Profile Built2026-06-28 17:02:49 UTC
Data FreshnessLive
Signal Types21
Total Observations24
๐Ÿ” 21 signal types ยท 24 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.