IP INTELLIGENCE BRIEFING: 15.235.27.112/32
THREAT ASSESSMENT SUMMARY
IP address 15.235.27.112 is classified as moderate risk with a risk score of 50. The IP is hosted on OVH infrastructure (ASN 16276, organization: Dmytro, Ahrefs Pte Ltd) within CIDR block 15.235.27.0/24. The subnet demonstrates high abuse characteristics with an abuse density score of 0.6406 and 164 threat siblings out of 256 total addresses.
NETWORK CONTEXT
The IP operates as cloud compute infrastructure with a PTR hostname of proxy-ca013-san112.ahrefs.net resolving to the ahrefs.net domain. DNS records indicate CAA and DNSSEC validation is active. No open ports or active services are detected; the IP is currently firewalled.
THREAT INDICATORS
- Blacklist presence: Listed on 2 of 8 threat feeds with maximum severity rated high
- Operator risk score: 0.2174 (minimal operator threat)
- No Tor exit node, known attacker, spam source, or active campaign associations
- Single threat observation recorded, not persistently malicious
- Route stability flagged as false with 0 route changes in the past 30 days
NEIGHBORHOOD ANALYSIS
The parent subnet 15.235.27.0/24 shows elevated abuse patterns. Of 100 sampled neighbor IPs, 100 presented medium-risk profiles (risk scores 40-50). Zero neighbors were classified as high risk, but the overall subnet abuse density of 0.6406 indicates concentrated malicious activity within this cloud hosting block.
OBSERVATION HISTORY
Seventeen observations recorded over the analysis period. Recent signals indicate consistent high-severity blacklist presence and maintained high-abuse classification. DNS and CAA resolution remained stable across all observations.
RECOMMENDED ACTIONS
Based on the risk profile, the following firewall rules are recommended for immediate implementation:
- iptables: `iptables -A INPUT -s 15.235.27.112 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 15.235.27.112 drop`
- nginx: `deny 15.235.27.112;`
- pfSense: `15.235.27.112/32`
- Cloudflare WAF: Block with expression `ip.src eq 15.235.27.112`
- AWS WAF: Add address `15.235.27.112/32` with description "IPDebrief risk 50"
INTELLIGENCE NOTES
While the IP lacks active service exposure, the combination of high-severity blacklist presence, elevated subnet abuse density, and association with the ahrefs.net infrastructure warrants continued monitoring. The moderate risk score and absence of confirmed malicious campaigns suggest opportunistic abuse rather than persistent threat actor activity.
---
*Report generated: 2026-06-15*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059692 |
| CIDR Block | 15.235.27.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca013-san112.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca013-san112.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 32% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 21% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-25 06:41:11 UTC |
| Last Seen | 2026-06-29 01:13:12 UTC |
| Profile Built | 2026-06-29 07:17:06 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 20 |
Full dossier details are available via our API.