# IP Intelligence Briefing: 51.89.129.235/32
## Executive Summary
IP 51.89.129.235 is a cloud-compute infrastructure address operated by Ahrefs Pte Ltd Dmytro (ASN 16276) with a moderate risk score of 50. The IP is located in London, England, on OVH hosting infrastructure and resolves to ahrefs.net with PTR hostname proxy-uk008-san235.ahrefs.net. Despite legitimate ownership, the IP resides within a high-abuse subnet (51.89.129.0/24) with an abuse density of 0.668.
## Profile Details
Ownership & Network Classification
- Organization: Ahrefs Pte Ltd Dmytro
- ASN: 16276
- Infrastructure Type: CloudCompute / Hosting
- Geolocation: London, England, GB
- Provider: OVH
DNS & Services
- Forward Resolution: proxy-uk008-san235.ahrefs.net
- PTR Hostname: proxy-uk008-san235.ahrefs.net
- Domain: ahrefs.net
- Open Ports: None detected
- Network Role: Firewall / No Services
Threat Indicators
- Risk Score: 50 (Moderate)
- Blacklist Count: 0
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaigns: None detected
- DNSBL Listed: 2 of 8 lists
Control Plane
- BGP Prefix: 51.89.0.0/16
- Route Stability: Unstable
- RPKI State: Not verified
- DNSSEC: Valid
## Neighborhood Analysis
The IP resides in subnet 51.89.129.0/24, classified as high abuse with the following characteristics:
- Abuse Density: 0.668 (High)
- Total Siblings: 256
- Active Siblings: 158
- Threat Siblings: 171
- Inherited Risk: 26
Risk distribution across the /24 subnet shows 100 medium-risk IPs, 0 high-risk IPs, and 0 low-risk IPs. This indicates the subnet contains legitimate infrastructure alongside malicious actors.
## Observation History
Analysis of 18 historical observations reveals a stable risk profile. Recent observations from June 2026 show consistent subnet abuse density (0.668) and operator scores (0.2174). No significant escalation in threat signals has been observed over the observation period.
## Recommended Actions
Based on the moderate risk score and high-abuse neighborhood context, the following firewall rules are recommended:
iptables: `iptables -A INPUT -s 51.89.129.235 -j DROP`
nftables: `nft add rule inet filter input ip saddr 51.89.129.235 drop`
nginx: `deny 51.89.129.235;`
Cloudflare WAF: Block with expression `ip.src eq 51.89.129.235`
AWS WAF: Block address `51.89.129.235/32`
## Assessment Notes
This IP appears to be legitimate Ahrefs infrastructure but operates within a high-abuse environment. The moderate risk score warrants monitoring but does not indicate active malicious behavior. SOC teams should evaluate context-dependent factors such as traffic patterns and organizational policies before implementing blocking measures. The high-abuse neighborhood suggests implementing subnet-level monitoring may be more effective than IP-specific blocking.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk008-san235.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk008-san235.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 39% | 2 | 3 |
| Overall | 23% | 10 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 21:28:57 UTC |
| Last Seen | 2026-06-28 08:05:47 UTC |
| Profile Built | 2026-06-29 02:10:09 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.