IP Intelligence Briefing: 15.235.27.132
Date: 2026-06-16
---
**1. Core Profile**
- Risk Assessment: Moderate Risk (Risk Score: 50/100). No direct malicious indicators (no malware, phishing, or known campaigns).
- Ownership:
- ASN: 16276 (OVH)
- Organization: Dmytro, Ahrefs Pte Ltd (OVH-CUST-281059692)
- Geolocation: Registered to Singapore (CA), but geo-validation is not plausible (potential spoofing or misconfiguration).
- Network Role: CloudCompute infrastructure (OVH-hosted). No open ports, no TLS services, no HTTP banners.
- DNS: Linked to `proxy-ca013-san132.ahrefs.net` (Ahrefs, a legitimate SEO tool). No DNS-based threats detected.
---
**2. Threat & Behavior**
- Threat Indicators:
- No known spam, attacker, or Tor exit node associations.
- High Abuse Subnet: 15.235.27.0/24 has 66.8% abuse density (171/256 IPs flagged as threats).
- Neighbor Risk: 100 neighbors analyzed; 98 medium/low risk, 2 high risk.
- Observation History:
- Recent signals show high abuse classification (0.668 density), but no persistent malicious activity.
- Operator score: Minimal (0.2174), but subnet instability (route changes) detected.
---
**3. Relationships & Context**
- Network Associations:
- Same subnet as OVH-CUST-281059692 (Ahrefs).
- DNS ties to `proxy-ca013-san132.ahrefs.net` (likely a legitimate proxy service).
- DNS & Certificates:
- No TLS certificates or HTTP services detected.
- DNSSEC and CAA records validated, but no email authentication (SPF/DKIM) found.
---
**4. Recommendations**
- Monitor Subnet: High abuse density in 15.235.27.0/24 suggests potential compromise. Investigate neighbors with high risk scores.
- Verify DNS Configuration: Ensure `proxy-ca013-san132.ahrefs.net` is legitimate and not misused for C2 or phishing.
- Firewall Rules:
- Block high-risk neighbors in 15.235.27.0/24.
- Restrict access to Ahrefsβ subnet if not required.
- Geo Validation: Investigate geo-plausibility discrepancies; consider spoofing or misconfigured routing.
---
Conclusion:
15.235.27.132 appears legitimate as part of Ahrefsβ CloudCompute infrastructure, but its subnet exhibits high abuse density. SOC teams should prioritize monitoring the subnet, validating DNS associations, and securing the network against potential lateral movement from compromised neighbors.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059692 |
| CIDR Block | 15.235.27.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca013-san132.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca013-san132.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 17% | 1 | 2 |
| geolocation | 32% | 2 | 3 |
| Overall | 20% | 9 | 11 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-08 19:45:50 UTC |
| Last Seen | 2026-06-21 15:13:14 UTC |
| Profile Built | 2026-06-21 15:21:50 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 22 |
Full dossier details are available via our API.