# IP Intelligence Briefing: 51.89.9.178/32
## Executive Summary
IP 51.89.9.178 presents moderate risk (score: 55/100) and is associated with hosting provider OVH BV (ASN 16276) in Berlin, NL. The IP resolves to nubokado.com with a DMARC configuration in place. No active services are detected; the IP is classified as firewalled with no open ports.
## Risk Profile
- Overall Risk Score: 55/100 (Moderate Risk)
- Provider Classification: OVH (Cloud Compute/Hosting)
- Infrastructure Type: Cloud hosting environment
- Reputation: Moderate Risk
- Stability Label: Unstable (null stability score)
## Geolocation & Ownership
- Country: Netherlands (NL)
- City: Berlin
- ASN: 16276 (OVH BV)
- Network Block: 51.89.0.0/16
- Registration Authority: ARIN
- Contact: Abuse contact available via RDAP
## Network Role & Services
- Infrastructure: Cloud hosting provider (OVH)
- Connection Type: Cloud infrastructure
- Service Purpose: Firewalled / No Services
- Open Ports: None detected
- TLS Certificate: None
- HTTP Title: None
## DNS Intelligence
- Reverse DNS (PTR): info15.nubokado.com
- Forward Resolution: nubokado.com โ info15.nubokado.com
- Forward Confirmed: False
- DMARC: Present (policy: reject)
- SPF: Not configured
- TXT Records: 0
- Hosted Domains: 0
## Threat Indicators
- DNSBL Listings: 3 of 8 total lists (high severity noted)
- Known Tor Exit: No
- Known Attacker: No
- Spam Source: No
- Abuse Confidence Score: Not available
- Campaign Likelihood: Not assessed
- Cert Matches: 0
## Control Plane Data
- RPKI State: Not available
- Route Changes (30d): 0
- Route Stability: False
- DNSSEC Valid: Yes
- Has CAA: No
- DNSBL Listed Count: 3
- Operator Score: 0.2609 (Basic)
## Neighborhood Analysis
- Subnet: 51.89.9.0/24
- Abuse Density: 0.5 (moderate)
- Classification: Mostly clean
- Total Siblings: 2
- Active Siblings: 1
- Threat Siblings: 1
- High Risk Neighbors: 0
- Medium Risk Neighbors: 1 (51.89.9.181, risk score: 55)
## Historical Observations
21 total observations recorded. Key events include:
| Date | Event |
|---|---|
| 2026-06-20 12:22:42 | DMARC removed (has_dmarc: false) |
| 2026-06-20 12:22:36 | Cloud/Hosting classification confirmed |
| 2026-06-15 12:28:08 | DMARC present (p=reject) |
| 2026-06-15 12:25:02 | DNSBL listings detected (3 lists, high severity) |
| 2026-06-15 12:24:04 | Operator score minimal (0.1304) |
DMARC configuration was present on June 15, 2026, but removed by June 20, 2026. DNSBL listings were observed on June 15 with high severity classifications.
## Relationships
- DNS Associations: info15.nubokado.com (repeated)
- Network Associations: OVH-DEDICATED-FO
## Recommended Actions
Priority: Increase Monitoring
- Action: Increase logging verbosity and review recent activity
- Severity: High (risk score 55/100)
Firewall Rules (Block Recommendation)
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 51.89.9.178 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 51.89.9.178 drop` |
| nginx | `deny 51.89.9.178;` |
| pfSense | `51.89.9.178/32` |
| Cloudflare WAF | Block rule: `ip.src eq 51.89.9.178` |
| AWS WAF | Address: `51.89.9.178/32` |
## Analyst Notes
This IP is part of a low-density hosting environment with one adjacent high-risk neighbor (51.89.9.181). The DMARC policy removal in the last week is notable and may indicate misconfiguration or infrastructure changes. The three DNSBL listings with high severity warrant investigation, particularly in the context of the DMARC policy change. No evidence of active scanning or exploitation was observed. The IP should be monitored for any changes in DNSBL status or service activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH BV |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | info15.nubokado.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | info15.nubokado.com |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 23% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 14:58:01 UTC |
| Last Seen | 2026-06-28 14:30:42 UTC |
| Profile Built | 2026-06-29 08:36:25 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.