IPDebrief

51.89.129.218

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Subject: 51.89.129.218/32

Classification: Cloud Infrastructure / Hosting

Date: 2026-06-26

Analyst: IPDebrief Intelligence

---

## EXECUTIVE SUMMARY

51.89.129.218 is a cloud-compute infrastructure IP assigned to Ahrefs Pte Ltd Dmytro, operated through OVH network infrastructure (ASN 16276). The IP resolves to a legitimate ahrefs.net hostname but exhibits DNSBL listings and moderate neighborhood abuse density. No active services detected on the target IP.

---

## INFRASTRUCTURE PROFILE

AttributeValue
**Risk Score**25/100 (Low Risk)
**Organization**Ahrefs Pte Ltd Dmytro
**ASN**16276 (OVH SAS)
**Network**51.89.0.0/16
**Geolocation**London, England, GB
**Infrastructure Type**Cloud Compute / Hosting
**DNS Resolution**proxy-uk008-san218.ahrefs.net

---

## THREAT INDICATORS

DNSBL Status: Listed on 1 of 8 threat feeds

Active Threat Indicators: None detected

Known Campaigns: No matches

Tor Exit/Proxy: Negative

Spam/Attacker Source: Negative

Notable: The IP maintains a forward resolution count of 1 but shows no forward-confirmed status, indicating potential DNS inconsistency.

---

## NEIGHBORHOOD ANALYSIS (51.89.129.0/24)

Observation: The target resides in a subnet with elevated abuse activity. While this specific IP shows low individual risk, 106 sibling IPs are classified as threats.

---

## OBSERVATION HISTORY

Total signals: 19 observations

Recent Signals (2026-06-26):

Temporal Indicators: No ownership changes detected. Threat persistence: 0 days.

---

## NETWORK RELATIONSHIPS

---

## RECOMMENDED ACTIONS

Firewall Rules:

```bash

# Block inbound connections to this IP

iptables -A INPUT -s 51.89.129.218 -j DROP

# Log and block subnet if false positives persist

iptables -A INPUT -s 51.89.129.0/24 -j LOG --log-prefix "BLOCK_AHREFS_NET: "

```

WAF Rules (Cloudflare/AWS):

```

# Block IP with 51.89.129.0/24 subnet

ip: 51.89.129.218, 51.89.129.0/24

action: block

```

Monitoring Recommendations:

1. Monitor for new services opening on this IP

2. Watch for DNSBL listing additions/removals

3. Correlate with other ahrefs.net infrastructure for lateral threat assessment

---

## ASSESSMENT

This IP represents legitimate Ahrefs infrastructure hosted on OVH cloud. However, the subnet exhibits moderate-to-high abuse density (0.4141), and the target IP carries one DNSBL listing. While individual risk is low (25), the neighborhood context suggests potential for abuse-related traffic. Recommend monitoring rather than immediate blocking unless specific threat activity is observed.

Confidence Level: High

Threat Priority: Low/Medium

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom
RegionENG
CityLondon
TimezoneEurope/London
Latitude51.51
Longitude-0.13

๐Ÿข Ownership & Registration

OrganizationAhrefs Pte Ltd Dmytro
ASNAS16276
Network Nameโ€”
CIDR Blockโ€”
RIRARIN
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRproxy-uk008-san218.ahrefs.net
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-uk008-san218.ahrefs.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
32%
23
routing
13%
11
services
12%
22
ownership
20%
23
reputation
21%
12
geolocation
35%
23
Overall22%1014
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-11 21:44:42 UTC
Last Seen2026-06-27 20:31:43 UTC
Profile Built2026-06-28 20:37:51 UTC
Data FreshnessLive
Signal Types21
Total Observations26
๐Ÿ” 21 signal types ยท 26 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.