## IP INTELLIGENCE BRIEFING: 15.235.27.225/32
Executive Summary
Target IP 15.235.27.225 is hosted on OVH cloud infrastructure (ASN 16276) under organization "Dmytro, Ahrefs Pte Ltd" within CIDR block 15.235.27.0/24. Risk assessment indicates Moderate Risk (Score: 50) with high-abuse subnet classification. No active threat indicators present, but operational context warrants defensive consideration.
Technical Profile
- Risk Score: 50 (Moderate Risk)
- Ownership: OVH-CUST-281059692, Dmytro, Ahrefs Pte Ltd
- Geolocation: Canada (CA) per RIR records; conflicting Singapore location data
- Infrastructure Type: Cloud Compute / Hosting
- DNS Resolution: proxy-ca013-san225.ahrefs.net
- Services: No open ports detected; no TLS certificate; service banner absent
- Network Role: Firewalled / No Services
Neighborhood Analysis (15.235.27.0/24)
- Abuse Density: 0.6406 (High Abuse Classification)
- Subnet Risk: Inherited Risk Score: 25
- Sibling Activity: 256 total IPs; 211 active; 164 threat siblings
- Neighbor Risk Distribution: 100 medium-risk IPs (0 high, 0 low)
- Control Plane: BGP prefix 15.235.0.0/17; route stability flagged as unstable
Threat Assessment
- Threat Indicators: None detected (0 blacklists)
- Campaign Correlation: No known campaigns
- Historical Persistence: Not persistently malicious (threat observation count: 1)
- Geolocation Validity: Flagged as implausible (distance >3000km)
- Recent Activity: 17 observations recorded (most recent: 2026-06-15)
Operational Context
Relationship graph shows 33 connections, primarily to same network (OVH-CUST-281059692). The subnet exhibits elevated abuse density with significant threat sibling count relative to total active siblings (164/211 = 78% threat ratio among active neighbors).
Defensive Recommendations
Firewall blocking recommended across platforms:
- iptables: `iptables -A INPUT -s 15.235.27.225 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 15.235.27.225 drop`
- Cloudflare WAF: Block IP with filter expression `ip.src eq 15.235.27.225`
- AWS WAF: Address `15.235.27.225/32`
Note: Recommendations are probabilistic and should be combined with additional contextual signals before enforcement.
Intelligence Conclusion
This IP presents moderate risk within a high-abuse hosting environment. While no direct threat indicators exist, the subnet's abuse density and high threat sibling ratio suggest defensive caution. Consider blocking at perimeter if traffic patterns warrant, particularly given the hosting infrastructure context.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059692 |
| CIDR Block | 15.235.27.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca013-san225.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca013-san225.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 40% | 2 | 3 |
| Overall | 26% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-23 12:22:08 UTC |
| Last Seen | 2026-06-28 21:09:27 UTC |
| Profile Built | 2026-06-29 03:12:46 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.