# IP INTELLIGENCE BRIEFING: 51.89.129.174
Date: 2026-06-15
Classification: Moderate Risk
## Executive Summary
IP 51.89.129.174 is a moderate-risk hosting endpoint operated by OVH SAS (ASN: 16276) in London, GB. The IP resolves to aframes.net infrastructure (proxy-uk008-san174.ahrefs.net) and is classified as hosting with firewalled/no services. While the individual IP shows no direct threat indicators, the /24 subnet exhibits elevated abuse density (0.668) with 171 threat-sibling IPs out of 256 total addresses.
## Profile Details
| Field | Value |
|---|---|
| **Risk Score** | 40 / 100 (Moderate) |
| **Organization** | Ahrefs Pte Ltd Dmytro |
| **ISP/Provider** | OVH SAS (AS16276) |
| **Location** | London, England, GB |
| **DNS** | proxy-uk008-san174.ahrefs.net |
| **Email Auth** | SPF/DMARC not configured |
| **Services** | None detected (firewalled) |
## Threat Assessment
- Direct Threat Indicators: None detected (blacklist count: 0, no known campaigns)
- Tor/Proxy: Not a Tor exit node or proxy
- Known Attacker: No
- Spam Source: Not flagged
- DNSBL Status: Listed on 1 of 8 threat feeds
## Neighborhood Context (51.89.129.0/24)
- Abuse Density: 0.668 (High Abuse Classification)
- Active Siblings: 156 / 256 addresses
- Threat Siblings: 171 addresses
- Risk Distribution: 100 medium-risk, 0 high-risk
- Inherited Risk Score: 26
This subnet shows elevated abuse activity relative to baseline, suggesting the provider or subnet block may be compromised by misconfigured or malicious tenants.
## Historical Observations (22 total)
- Recent signals indicate consistent subnet-level abuse density (0.668)
- Operator score: 0.2174 (Minimal)
- Route stability: Stable (0 changes in 30 days)
- DNSSEC: Valid
- No persistent malicious activity pattern observed
## Recommended Actions
1. Monitor Closely: Due to high-abuse subnet classification, implement enhanced logging and monitoring for this IP and related /24 subnet
2. Block if Needed: If the IP exhibits suspicious outbound connections, consider temporary block with whitelist override for legitimate traffic
3. Subnet Analysis: Review additional IPs in 51.89.129.0/24 for correlated activity patterns
4. Email Filtering: Apply strict email filtering rules for ahrefs.net domains (no SPF/DMARC configured)
## SOC Analyst Notes
This IP is associated with Ahrefs infrastructure but is hosted on OVH. The moderate risk score combined with the high-abuse neighborhood suggests either legitimate hosting with compromised neighbors or legitimate infrastructure under attack. Monitor for anomalous behavior rather than assuming malicious intent. The absence of open ports indicates the IP is likely a backend infrastructure address rather than a public-facing service.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk008-san174.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk008-san174.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 25% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 09:25:05 UTC |
| Last Seen | 2026-06-28 07:16:49 UTC |
| Profile Built | 2026-06-29 01:22:03 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 26 |
Full dossier details are available via our API.