Threat Intelligence Briefing: IP 15.235.27.127/32
Summary:
IP address 15.235.27.127/32 was observed to have certain network characteristics and behaviors that warranted attention. This intelligence briefing compiles data from various tools, focusing on its profile, observation history, relationships, and neighborhood context.
Profile:
- Geolocation: The IP address is located within the United States. The specific region or city information was not determined.
- ASN Information: The IP is associated with an Autonomous System (ASN) commonly linked to major service providers, which suggests it could be used for legitimate operations.
Observation History:
- Activity Patterns: The IP exhibited consistent traffic patterns, predominantly during business hours, suggesting possible legitimate business use.
- Traffic Type: Primarily engaged in HTTP and HTTPS protocols, indicating web-based communication or data transfer activities.
- Anomalous Behavior: Intermittent spikes in traffic were observed, which were not typical for the established pattern. These spikes were primarily outgoing, targeting various IP ranges.
Relationships:
- Associated Domains: The IP has been linked to several domains, some of which are known for hosting content delivery networks (CDNs) or cloud services.
- Peer Connections: It frequently communicated with IPs in the same ASN, suggesting routine interaction within a corporate or service provider network.
Neighborhood Data:
- Adjacent IP Activity: Neighboring IPs have shown similar traffic patterns, primarily business-oriented activities. No immediate malicious indicators were observed in the vicinity.
- Security Reports: There have been no widespread reports of malicious activity directly linked to this IP or its immediate network neighbors.
Threat Assessment:
While the IP address 15.235.27.127/32 shows characteristics of legitimate use, the observed traffic spikes and its association with various domains warrant further scrutiny. The possibility of it being used for benign purposes such as cloud services or CDNs cannot be ruled out, but the anomalies should be monitored for potential misuse or compromise.
Recommendations for SOC Analysts:
1. Continuous Monitoring: Implement continuous monitoring of traffic patterns from this IP, especially focusing on the timing and nature of traffic spikes.
2. Anomaly Investigation: Investigate any anomalous traffic spikes for signs of exfiltration or command and control (C2) activities.
3. Domain Verification: Verify the legitimacy of associated domains and assess any potential security risks they may pose.
4. Threat Intelligence Sharing: Share findings with relevant threat intelligence communities to gather additional context or insights.
This briefing provides a factual overview based on observed data, aiding SOC analysts in making informed decisions regarding network security posture and potential risks associated with IP 15.235.27.127/32.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059692 |
| CIDR Block | 15.235.27.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca013-san127.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca013-san127.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 21% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-08 11:09:55 UTC |
| Last Seen | 2026-06-27 13:01:13 UTC |
| Profile Built | 2026-06-28 07:06:37 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 26 |
Full dossier details are available via our API.