# INTELLIGENCE BRIEFING: 15.235.27.35/32
Classification: Moderate Risk - Cloud Infrastructure
Date: 2026-06-20
Assigned Analyst: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
IP 15.235.27.35 is a cloud-compute infrastructure address hosted on OVH network (ASN 16276) under organization Dmytro, Ahrefs Pte Ltd. The IP resolves to ahostname proxy-ca013-san35.ahrefs.net within the Ahrefs domain ecosystem. While the IP itself shows no active threat indicators, it resides within a subnet (15.235.27.0/24) exhibiting elevated abuse density at 58.59%, with 150 out of 256 sibling IPs classified as threat sources. Geographic validation inconsistencies detected between claimed location (Quebec, Canada) and network latency measurements.
---
## TECHNICAL PROFILE
| Attribute | Value |
|---|---|
| **Risk Score** | 40 (Moderate Risk) |
| **Provider** | OVH (Cloud Compute) |
| **Geolocation** | CA (Quebec) - Validation: False |
| **Infrastructure Type** | Cloud Hosting |
| **Open Ports** | None (Firewalled) |
| **DNS Classification** | Forward confirmed: proxy-ca013-san35.ahrefs.net |
| **DNSBL Listed** | 1 of 8 lists |
| **BGP Prefix** | 15.235.0.0/17 |
---
## THREAT ASSESSMENT
Current Threat Indicators: None active
- No known attack campaigns correlated
- Not identified as Tor exit node, proxy, or known spam source
- No active threat feeds matches
Network Context:
- Subnet abuse density: 58.59% (High)
- Threat siblings: 150 of 256 IPs
- Inherited risk score: 23
Geographic Anomalies:
- Claimed location: Quebec, Canada
- RTT measurement: 25ms average vs minimum possible 121.6ms for 6082km distance
- Geographic validation: Failed (plausible: false)
- Suggests potential location spoofing or proxy routing
---
## OBSERVATION HISTORY
Total Observations: 23 signals tracked
- Recent Activity: Operator score 0.2174 (Minimal)
- Subnet Classification: High abuse (observed 2026-06-15)
- Geolocation Consensus: Inconsistent across probes
- Threat Persistence: Not persistently malicious
---
## NETWORK RELATIONSHIPS
- 33 relationships identified
- Primary association: OVH-CUST-281059692 (same network)
- All relationships classified as same-network associations
- No external entity or organizational links beyond OVH infrastructure
---
## NEIGHBORHOOD ANALYSIS
Sampled Neighbors (100 of 256):
- High risk: 0
- Medium risk: 100
- Low risk: 0
- Risk score distribution: Clustered 40-50
Key Neighbor IPs:
- 15.235.27.0: Risk 40, Authority 50
- 15.235.27.1: Risk 40, Authority 50
- 15.235.27.3: Risk 50, Authority 50
---
## RECOMMENDED ACTIONS
1. Monitor subnet 15.235.27.0/24 for elevated activity patterns given 58.59% abuse density
2. Block if necessary - No active indicators but elevated neighborhood risk
3. Investigate geographic discrepancies - RTT violations suggest potential proxy usage
4. Allow with logging - Ahrefs infrastructure may be legitimate; monitor for abuse patterns
5. Review DNSBL listings - Single listing may warrant investigation of specific blocklist
---
## INTELLIGENCE NOTE
This IP represents cloud hosting infrastructure for Ahrefs (SEO analytics platform), a legitimate service. However, the subnet context indicates shared hosting environment with elevated abuse density. Geographic validation failures and RTT anomalies suggest potential for proxy or VPN routing through this infrastructure. Recommended: Monitor rather than block, with logging enabled for abuse detection.
---
END BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059692 |
| CIDR Block | 15.235.27.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca013-san35.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca013-san35.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 14:56:16 UTC |
| Last Seen | 2026-06-28 13:43:30 UTC |
| Profile Built | 2026-06-29 07:49:48 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.