IP INTELLIGENCE BRIEFING: 15.235.27.231/32
EXECUTIVE SUMMARY
IP address 15.235.27.231 is assigned to OVH infrastructure (ASN 16276, Organization: Dmytro, Ahrefs Pte Ltd) within the 15.235.27.0/24 subnet. The IP carries a moderate risk score of 50 and shows evidence of DNSBL listings. The subnet exhibits high abuse classification with 66.02% abuse density.
OWNERSHIP & INFRASTRUCTURE
- ASN: 16276 (OVH)
- Network Block: 15.235.27.0/24
- Infrastructure Type: Cloud/Hosting environment
- Service Status: Firewalled / No Services detected (no open ports, no TLS certificates)
- DNS Resolution: proxy-ca013-san231.ahrefs.net (ahrefs.net domain)
- Geolocation: Singapore (geo validation flaggedβRTT discrepancy of 6,082km with minimum possible 121.6ms)
THREAT INDICATORS
- Risk Score: 50 (Moderate Risk)
- DNSBL Status: Listed on 2 of 8 threat feeds
- Threat Indicators: None directly attributed to this IP
- Campaign Affiliation: None detected
- Known Attacker/SpamSource: Not flagged
NEIGHBORHOOD ANALYSIS
The 15.235.27.0/24 subnet shows elevated risk characteristics:
- Active Siblings: 219 of 256 IPs active
- Threat Siblings: 169 IPs flagged as threats
- Abuse Density: 0.6602 (High Abuse Classification)
- Inherited Risk: 26
- Risk Distribution: 100 medium-risk IPs detected in neighborhood
OBSERVATION HISTORY
Recent signal activity (22 total observations) indicates:
- Most recent probe: 2026-06-26T02:12:49Z
- DNSBL listing detected with high severity
- Cloud infrastructure confirmed
- Ahrefs.net domain association
- Operator score: 0.2174 (Minimal)
- Route stability: False (dynamic BGP routing)
NETWORK CLASSIFICATION
- Provider: OVH (cloud hosting provider)
- Connection Type: CloudCompute
- Is Residential: No
- Is Proxy/VPN/Tor: No
- Is AnyCast: No
RECOMMENDED SECURITY ACTIONS
The following rules are recommended based on the risk profile:
- iptables: `iptables -A INPUT -s 15.235.27.231 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 15.235.27.231 drop`
- nginx: `deny 15.235.27.231;`
- pfSense: Add 15.235.27.231/32 to block list
- Cloudflare WAF: Block IP with expression `ip.src eq 15.235.27.231`
- AWS WAF: Configure rule for CIDR `15.235.27.231/32`
INTELLECUAL NOTE
The IP resolves to the ahrefs.net domain but shows no active web services. The geo-location discrepancy (Singapore reporting vs. actual network location) suggests potential routing manipulation or geolocation data inconsistency. The subnet's high abuse density warrants consideration of blocking the entire /24 block if organizational policy permits, though this may impact legitimate ahrefs.net services.
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059692 |
| CIDR Block | 15.235.27.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca013-san231.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca013-san231.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Mixed Signals (60%) β 2 contradiction(s) |
| Attribution | Very Low (20%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
β Geo sources disagree on country: US, CA
π Observation Timeline π Live
| First Seen | 2026-05-10 16:14:00 UTC |
| Last Seen | 2026-06-27 17:48:56 UTC |
| Profile Built | 2026-06-28 11:54:10 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 28 |
Full dossier details are available via our API.