# INTELLIGENCE BRIEFING: 51.89.129.53/32
Classification: Moderate Risk | Risk Score: 40/100
Date: June 2026 | Status: Active Monitoring
---
## EXECUTIVE SUMMARY
IP address 51.89.129.53 is a cloud-hosted infrastructure endpoint operated by OVH (ASN 16276) within the Ahrefs Pte Ltd Dmytro organization. The IP is geolocated to London, United Kingdom, and resolves to aresolves to hostname proxy-uk008-san53.ahrefs.net. While the endpoint itself shows no active malicious indicators, it resides within a high-abuse subnet (51.89.129.0/24) with a 74.61% abuse density rating.
---
## TECHNICAL PROFILE
Network Classification:
- Infrastructure Type: Cloud Compute / Hosting
- Provider: OVH (ASN 16276)
- Network Block: 51.89.0.0/16
- Geolocation: London, England, GB (Europe/London timezone)
- DNS Resolution: proxy-uk008-san53.ahrefs.net (ahrefs.net)
Service Exposure:
- Open Ports: None detected
- Services: Firewalled / No Services Running
- TLS/Certificates: None observed
- HTTP Services: None accessible
Threat Indicators:
- Blacklist Status: Listed on 8 DNS blacklist sources (1 active listing with high severity)
- Campaign Association: None identified
- Known Attacker: No
- Spam Source: No
- Tor Exit/VPN/Proxy: Negative
---
## NEIGHBORHOOD ANALYSIS
Subnet: 51.89.129.0/24
- Abuse Density: 0.7461 (High Abuse Classification)
- Active Siblings: 194 / 256 total
- Threat Siblings: 191 endpoints
Risk Distribution:
- High Risk: 0 endpoints
- Medium Risk: 52 endpoints
- Low Risk: 48 endpoints
Assessment: The IP operates within an OVH hosting subnet with elevated abuse activity. While 51.89.129.53 itself shows no active threat signatures, the high neighborhood abuse density warrants contextual awareness.
---
## OBSERVATION HISTORY
Total Observations: 23 signals recorded
Key Timeline Events:
- June 28, 2026: Listed across 8 DNS blacklist categories (maximum severity: high)
- June 20, 2026: Provider attribution confirmed to OVH; geographic validation showed plausible London location (473.7km from reference point, 87ms RTT)
- Geographic Consistency: RTT measurements and claimed coordinates consistently validate London placement
---
## RELATIONSHIP GRAPH
Identified Relationships: 36 total
- Primary: Multiple same-network relationships (OVH_282347344)
- Network Affiliation: OVH cloud infrastructure
- Domain Association: ahrefs.net (1 forward-confirmed hostname)
---
## RECOMMENDED ACTIONS
Immediate Mitigation:
```bash
# iptables
iptables -A INPUT -s 51.89.129.53 -j DROP
# nftables
nft add rule inet filter input ip saddr 51.89.129.53 drop
# nginx
deny 51.89.129.53;
```
Cloud Platform Rules:
- Cloudflare WAF: Block with filter `ip.src eq 51.89.129.53`
- AWS WAF: Add to IPSet with CIDR 51.89.129.53/32
Contextual Considerations:
- The IP shows no active threat indicators but resides in a high-abuse subnet
- Monitor for changes in blacklist status and threat persistence
- Consider subnet-level blocking if business context warrants (191 threat siblings in /24)
---
## ANALYST NOTES
This endpoint represents a cloud-hosted infrastructure resource with a moderate risk profile. The absence of open services and active threat indicators suggests legitimate hosting use, though the high neighborhood abuse density indicates potential for collateral risk. Recommend monitoring for any changes in service exposure or blacklist status. No immediate blocking required unless specific threat intelligence emerges.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk008-san53.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk008-san53.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 39% | 2 | 3 |
| Overall | 25% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 21:40:49 UTC |
| Last Seen | 2026-06-28 10:17:47 UTC |
| Profile Built | 2026-06-29 04:22:34 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 27 |
Full dossier details are available via our API.