IP INTELLIGENCE BRIEFING: 51.89.129.76
EXECUTIVE SUMMARY
The IP address 51.89.129.76 is a moderate-risk (risk score 40) infrastructure IP belonging to Ahrefs Pte Ltd Dmytro, hosted on OVH Cloud (ASN 16276) in London, GB. The address operates within a high-abuse subnet (51.89.129.0/24) with 0.668 abuse density. No active threat indicators were detected, but contextual risk factors suggest defensive blocking is warranted.
INFRASTRUCTURE PROFILE
The IP resolves to hostnames proxy-uk008-san76.ahrefs.net and operates within a cloud compute environment. No services are currently running on the address (firewalled/no services detected). The infrastructure is classified as hosting infrastructure with stable network characteristics. The IP maintains valid DNSSEC, CAA records, and passes geo-validation checks.
THREAT ASSESSMENT
Current threat indicators show no active malicious activity:
- Not identified as a known attacker
- Not a Tor exit node
- Not a known spam source
- Blacklist count: 0
- DNSBL: Listed on 1 of 8 threat feeds
However, the inherited risk from the subnet contributes 26 points to the overall risk score. The address shows minimal operator score (0.2174) across recent observations.
SUBNET CONTEXTUAL RISK
The /24 subnet (51.89.129.0/24) exhibits elevated abuse characteristics:
- Total siblings: 256
- Active siblings: 170
- Threat siblings: 171
- Risk distribution across sampled neighbors: 100 medium-risk instances (risk score 40)
- Classification: high_abuse
- Inherited risk score: 26
OBSERVATION HISTORY
Analysis of 25 signal observations reveals:
- Consistent operator score of 0.2174 ("Minimal")
- No persistent malicious activity detected
- Single threat observation recorded
- Stable ownership over time
RECOMMENDED ACTIONS
Based on the moderate risk profile and high-abuse subnet context, the following defensive measures are recommended:
Firewall Rules:
- iptables: `iptables -A INPUT -s 51.89.129.76 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 51.89.129.76 drop`
- nginx: `deny 51.89.129.76;`
WAF/Cloud Platform Rules:
- Cloudflare WAF: Block with expression `ip.src eq 51.89.129.76`
- AWS WAF: Add address `51.89.129.76/32` to rule set with description "IPDebrief risk 40"
- pfSense: 51.89.129.76/32
INTEL NOTE: While the IP shows no active threat indicators, the high-abuse subnet context and moderate risk score warrant blocking. This is a defensive measure based on contextual risk rather than confirmed malicious activity.
SOC TEAM: Monitor for any changes in threat indicators or subnet-wide abuse patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk008-san76.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk008-san76.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-20 11:47:01 UTC |
| Last Seen | 2026-06-28 11:59:46 UTC |
| Profile Built | 2026-06-29 06:07:56 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.