IP Intelligence Briefing: 51.89.129.72
Overview
IP 51.89.129.72 is registered to Ahrefs Pte Ltd Dmytro (ASN 16276, OVH) and resolves to proxy-uk008-san72.ahrefs.net in London, England. The IP operates within cloud compute infrastructure and is currently firewalled with no open services detected. Risk assessment indicates moderate threat level (score 40/100).
Network Context
The IP resides in subnet 51.89.129.0/24, which exhibits high abuse density (0.6406) with 164 threat siblings out of 155 active siblings. The subnet inherited risk score of 25, indicating elevated neighborhood-level threat activity. All neighboring IPs show medium risk classification with authority scores of 50.
Threat Indicators
- Blacklist presence: Listed on 1 of 8 DNSBLs
- No active threat indicators (not known attacker, not spam source, not Tor exit node)
- No associated malware campaigns or certificate anomalies
- No open ports or services detected via active scanning
Temporal Analysis
24 signal observations recorded across recent monitoring periods. Key observations:
- Subnet abuse density consistently classified as high (0.6406)
- Geolocation signals confirm UK location with multi-signal inference
- DNS resolution stable to ahrefs.net domain
- No persistent malicious behavior patterns detected
Relationships
61 identified relationships, primarily same-network associations with OVH infrastructure identifier OVH_282347344. No organizational or hostname relationships beyond the ahrefs.net domain association.
Recommended Actions
Given the moderate risk score and neighborhood abuse context, the following mitigation actions are recommended:
Firewall Rules:
- iptables: `iptables -A INPUT -s 51.89.129.72 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 51.89.129.72 drop`
- nginx: `deny 51.89.129.72;`
- pfSense: `51.89.129.72/32`
- Cloudflare WAF: Block with expression `ip.src eq 51.89.129.72`
- AWS WAF: Add `51.89.129.72/32` to IP set
Assessment Notes
This IP appears to be part of Ahrefs' proxy infrastructure. While not directly flagged as malicious, the high-abuse neighborhood context warrants traffic filtering. Monitor for any behavioral changes that may indicate compromised proxy usage.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | 51.89.0.0/16 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk008-san72.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk008-san72.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 27% | 3 | 4 |
| reputation | 31% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 28% | 12 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-15 08:44:35 UTC |
| Last Seen | 2026-06-28 02:13:17 UTC |
| Profile Built | 2026-06-28 20:19:29 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 29 |
Full dossier details are available via our API.