# IP Intelligence Briefing: 51.89.129.48/32
## Executive Summary
IP 51.89.129.48 is a moderate-risk (40/100) cloud hosting IP address associated with OVH infrastructure in London, England. The address belongs to Ahrefs Pte Ltd Dmytro and resolves to the ahrefs.net domain. The IP exhibits a "firewalled / no services" operational state with no active open ports. While the individual IP shows moderate risk, the /24 subnet (51.89.129.0/24) demonstrates high abuse density (0.7461) with 74.6% of active siblings flagged as threats.
## Ownership and Geolocation
- ASN: 16276 (OVH)
- Organization: Ahrefs Pte Ltd Dmytro
- Location: London, England, GB
- Infrastructure Type: CloudCompute (Cloud hosting)
- Registration: ARIN
## Network Characteristics
- DNS Resolution: proxy-uk008-san48.ahrefs.net
- PTR Record: proxy-uk008-san48.ahrefs.net
- Service Status: Firewalled / No Services Detected
- TLS/Certificates: None observed
- DNSBL Listed: 1 of 8 threat feeds
## Threat Profile
- Risk Score: 40 (Moderate Risk)
- Abuse Confidence: Not applicable (no active threat indicators)
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Known Campaigns: None
- Threat Feeds: Empty
## Subnet Intelligence (51.89.129.0/24)
- Total Siblings: 256
- Active Siblings: 194
- Threat Siblings: 191 (98.5% threat rate)
- Abuse Density: 0.7461 (High Abuse Classification)
- Inherited Risk Score: 29
- Risk Distribution: 58 medium-risk, 42 low-risk neighbors
## Behavioral History
Observation history indicates consistent cloud hosting behavior across multiple observation windows. The IP has maintained stable infrastructure characteristics with no significant ownership changes. Recent observations (June 2026) confirm continued OVH cloud compute classification.
## Recommended Actions
Given the high-abuse subnet context and moderate individual risk score, the following defensive measures are recommended:
Firewall Rules:
- `iptables -A INPUT -s 51.89.129.48 -j DROP`
- `nft add rule inet filter input ip saddr 51.89.129.48 drop`
- `nginx: deny 51.89.129.48;`
WAF Rules:
- Cloudflare WAF: Block with expression `ip.src eq 51.89.129.48`
- AWS WAF: Add address `51.89.129.48/32` to rule set
SOC Guidance: Consider blocking traffic from the entire /24 subnet (51.89.129.0/24) due to the 98.5% threat sibling rate, or apply enhanced monitoring to this IP class. The high abuse density suggests coordinated malicious activity within this subnet.
---
*Report generated for defensive security operations. Verify against internal threat intelligence before implementing blocking measures.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk008-san48.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk008-san48.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 09:25:06 UTC |
| Last Seen | 2026-06-28 07:18:48 UTC |
| Profile Built | 2026-06-29 01:23:10 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.