# IP INTELLIGENCE BRIEFING
Target: 15.235.27.44/32 | Classification: Moderate Risk (Score: 40) | Date: 2026-06-17
---
## EXECUTIVE SUMMARY
IP 15.235.27.44 is a cloud infrastructure address registered to Ahrefs Pte Ltd via OVH (ASN 16276). The IP presents moderate risk due to high-abuse subnet context and geolocation anomalies, with no confirmed active threat campaigns. Recommended action: Monitor inbound traffic; no immediate blocking required.
---
## OWNERSHIP & INFRASTRUCTURE
| Field | Value |
|---|---|
| ASN | 16276 |
| Organization | Dmytro, Ahrefs Pte Ltd |
| Netname | OVH-CUST-281059692 |
| RIR | ARIN |
| CIDR Block | 15.235.27.0/24 |
| Infrastructure Type | Cloud Compute / Hosting |
| Status | Active |
DNS Resolution: proxy-ca013-san44.ahrefs.net (ahrefs.net)
- SPF/DMARC: Not configured
- DNSSEC: Valid
- Certificate Authority Records: Present
---
## GEOLOCATION ANALYSIS
| Metric | Value | Status |
|---|---|---|
| Claimed Location | Singapore, CA | โ ๏ธ Flagged |
| Distance from Claim | 6082km | |
| Observed RTT | 27ms | โ ๏ธ Violation |
| Minimum Possible RTT | 121.6ms | |
| Geo Validation | Failed |
Assessment: Geolocation data is inconsistent. The 27ms RTT contradicts the claimed 6082km distance, indicating potential spoofing or routing anomaly.
---
## THREAT INDICATORS
- Risk Score: 40 (Moderate)
- Blacklist Count: 0
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- DNSBL Listed: 1 of 8 lists
Control Plane:
- BGP Prefix: 15.235.0.0/17
- Route Stability: Unstable
- Route Changes (30d): 0
- RPKI State: Not reported
---
## NEIGHBORHOOD CONTEXT
Subnet: 15.235.27.0/24
- Abuse Density: 0.6953 (High Abuse)
- Total Siblings: 256
- Active Siblings: 217
- Threat Siblings: 178
- Inherited Risk: 27
Risk Distribution: All sampled neighbors (100) show medium-risk scores (40-50).
---
## NETWORK SERVICES
- Open Ports: None detected
- TLS Certificate: None
- HTTP Title: None
- Server Banner: None
- Classification: Firewalled / No Services
---
## OBSERVATION HISTORY
Total Signals: 23 observations
Recent Activity:
- Subnet abuse density: 0.6953 (high_abuse)
- Operator score: 0.2174 (minimal)
- Ownership changes: 0
- Threat persistence days: 0
Signal Confidence Range: 0.24 - 0.85
---
## RELATIONSHIPS
Total Relationships: 45
- Primary: Same Network (OVH-CUST-281059692)
- No external organization or certificate relationships identified
---
## SECURITY ACTIONS RECOMMENDED
For SOC Analysts:
1. Monitor traffic from 15.235.27.0/24 subnet due to high abuse density
2. Review inbound connections for anomalous patterns given geolocation inconsistency
3. Track DNS queries to ahrefs.net for potential C2 indicators
Firewall Rules (Example):
```bash
# Block subnet-wide if required (monitor first)
iptables -A INPUT -s 15.235.27.0/24 -j DROP
```
Risk Mitigation:
- No immediate blocking required
- Enable logging for traffic from this subnet
- Monitor for changes in geolocation consistency
---
## CONCLUSION
IP 15.235.27.44 is a legitimate cloud host with no active threat indicators. The primary concern is the high-abuse subnet context and geolocation anomalies. Maintain monitoring posture but no immediate containment actions recommended.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059692 |
| CIDR Block | 15.235.27.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca013-san44.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca013-san44.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:45 UTC |
| Last Seen | 2026-06-27 00:04:48 UTC |
| Profile Built | 2026-06-27 14:16:48 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 26 |
Full dossier details are available via our API.