# IP Intelligence Briefing: 51.89.129.55/32
## Executive Summary
IP address 51.89.129.55 is a moderate-risk (40/100) infrastructure address hosted on OVH cloud compute infrastructure in London, GB. While no active threat indicators are present, the IP resides in a high-abuse density subnet (51.89.129.0/24) with 75% abuse density and 192 threat-sibling IPs. SOC analysts should monitor for policy-based blocking due to neighborhood risk concentration.
## Technical Profile
Ownership & Provider: ASN 16276, Ahrefs Pte Ltd Dmytro (OVH). CIDR block 51.89.0.0/16.
Geolocation: London, England, GB. Accuracy radius 750km.
Network Classification: CloudCompute infrastructure, firewalled/no active services detected.
DNS Resolution: proxy-uk008-san55.ahrefs.net (ahrefs.net domain). No reverse DNS confirmation.
## Threat Assessment
Risk Score: 40/100 (Moderate Risk)
Abuse Confidence: No active threat indicators; not a Tor exit node, known attacker, or spam source.
Blacklist Status: Listed on 1 of 8 DNS blacklists.
Known Campaigns: None detected.
Neighborhood Risk: The /24 subnet (51.89.129.0/24) shows elevated threat concentration:
- Abuse density: 0.75 (high_abuse classification)
- Active siblings: 194/256
- Threat siblings: 192
- Inherited risk score: 30/100
## Historical Signal Analysis
25 observations recorded. Recent signal activity (June 2026) confirms:
- Abuse density maintained at 0.75
- High-abuse classification persisted
- DNS resolution to ahrefs.net domain confirmed
- Operator score: 0.4348 (Basic)
## Relationship Graph
42 relationships identified, predominantly same-network links (OVH_282347344). No inter-organization or cross-subnet associations detected.
## Recommended Security Actions
Firewall Rules (Block IP):
- iptables: `iptables -A INPUT -s 51.89.129.55 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 51.89.129.55 drop`
- nginx: `deny 51.89.129.55;`
- pfSense: `51.89.129.55/32`
- Cloudflare WAF: Block with expression `ip.src eq 51.89.129.55`
- AWS WAF: Add to blacklist for address 51.89.129.55/32
## Intelligence Notes
The IP resolves to an official ahrefs.net proxy hostname but lacks service banner detection. The primary risk factor is neighborhood abuse density rather than intrinsic threat activity. Blocking is recommended for network hygiene, though the IP itself shows no active malicious behavior. Monitor for escalation in threat indicators.
---
*Report generated from IPDebrief intelligence platform. Recommendations should be combined with additional contextual signals before operational action.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | 51.89.0.0/16 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk008-san55.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk008-san55.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 20% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 22% | 3 | 4 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 12 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 23:50:44 UTC |
| Last Seen | 2026-06-28 10:43:22 UTC |
| Profile Built | 2026-06-29 04:48:48 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 31 |
Full dossier details are available via our API.