# IP INTELLIGENCE BRIEFING
Target: 15.235.27.113/32
Date: Current
Classification: Moderate Risk
---
## Executive Summary
IP address 15.235.27.113 is assigned to OVH hosting infrastructure under customer organization Ahrefs Pte Ltd (ASN 16276). The IP carries a moderate risk score of 40 and is part of a high-abuse density subnet (15.235.27.0/24) with a 0.7109 abuse density rating. The IP shows no active threat indicators in current profiles but operates within a neighborhood containing 182 identified threat siblings.
---
## Network Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 40 (Moderate Risk) |
| **ASN** | 16276 |
| **Organization** | Ahrefs Pte Ltd (Dmytro) |
| **Netname** | OVH-CUST-281059692 |
| **CIDR Block** | 15.235.27.0/24 |
| **Provider** | OVH |
| **Infrastructure Type** | Cloud Hosting |
---
## Geolocation Analysis
- Reported Country: CA (Canada)
- Reported City: Singapore
- Validation Status: โ ๏ธ GEOLOCATION INCONSISTENT
- RTT Anomaly: 26ms measured RTT violates minimum possible RTT of 121.6ms for 6082km distance to Singapore
- Accuracy Radius: 3000km
The geolocation data contains contradictory signals with country code "CA" conflicting with city "Singapore," and RTT measurements indicate the data is unreliable.
---
## DNS and Hostname Intelligence
| Field | Value |
|---|---|
| **PTR Hostname** | proxy-ca013-san113.ahrefs.net |
| **Forward Resolution** | proxy-ca013-san113.ahrefs.net |
| **Domain** | ahrefs.net |
| **Forward Confirmed** | No |
The PTR record resolves to a hostname associated with Ahrefs infrastructure. Forward confirmation failed.
---
## Threat Indicators
- Abuse Confidence Score: Not available
- Blacklist Count: 0
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Known Campaigns: None detected
- Threat Feeds: Empty
Current Threat Posture: No active threat indicators present in the IP profile.
---
## Network Neighborhood Assessment
The IP resides in subnet 15.235.27.0/24 with the following characteristics:
| Metric | Value |
|---|---|
| **Abuse Density** | 0.7109 (High) |
| **Subnet Classification** | high_abuse |
| **Total Siblings** | 256 |
| **Active Siblings** | 223 |
| **Threat Siblings** | 182 |
| **Inherited Risk** | 28 |
Risk distribution among neighbors: 0 high-risk, 59 medium-risk, 41 low-risk.
---
## Service Exposure
- Open Ports: None detected
- TLS Certificate: Not available
- HTTP Title: Not available
- Service Purpose: Firewalled / No Services
The IP shows no active services and appears firewalled.
---
## Historical Observations
- Total Observations: 23
- Recent Signal Types:
- Cloud infrastructure classification (2026-06-28)
- High-abuse subnet classification (2026-06-20)
- Geolocation signals (2026-06-20)
- Threat Persistence Days: 0
- Ownership Changes: 0
The IP has been consistently classified within a high-abuse subnet with no ownership changes.
---
## Recommended Actions
Based on the moderate risk score and high-abuse subnet environment, the following firewall rules are recommended:
```bash
# iptables
iptables -A INPUT -s 15.235.27.113 -j DROP
# nftables
nft add rule inet filter input ip saddr 15.235.27.113 drop
# Cloudflare WAF
{"description":"Block 15.235.27.113 โ IPDebrief risk score 40","action":"block","filter":{"expression":"ip.src eq 15.235.27.113"}}
# AWS WAF
{"Addresses":["15.235.27.113/32"],"Description":"IPDebrief risk 40"}
```
---
## Intelligence Notes
1. Subnet Risk: The /24 subnet (15.235.27.0/24) is classified as high_abuse with 182 threat siblings out of 223 active IPs. This suggests the entire subnet warrants elevated scrutiny.
2. Geolocation Reliability: The geolocation data is unreliable due to RTT violations and country/city mismatches. Do not rely on country or city for threat correlation.
3. Infrastructure Context: The IP is hosted on OVH cloud infrastructure with no active services detected. The PTR hostname indicates association with Ahrefs.net infrastructure.
4. Action Threshold: While the IP carries no active threat indicators, the high-abuse density of its subnet (0.7109) and the presence of 182 threat siblings suggest defensive blocking is warranted as a precautionary measure.
---
Analyst: IPDebrief Intelligence Team
Status: Complete
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059692 |
| CIDR Block | 15.235.27.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca013-san113.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca013-san113.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 22% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 22% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-23 12:22:07 UTC |
| Last Seen | 2026-06-28 21:07:06 UTC |
| Profile Built | 2026-06-29 09:10:27 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.