# IP Intelligence Briefing: 15.235.27.72/32
Classification: Moderate Risk / Legitimate Cloud Infrastructure
Date: 2026-06-28
Analyst: IPDebrief Intelligence
---
## Executive Summary
IP 15.235.27.72 is assigned to OVH cloud infrastructure under Ahrefs Pte Ltd ownership. The IP carries a moderate risk score of 40 with no active threat indicators. However, the /24 neighborhood (15.235.27.0/24) exhibits elevated abuse density (0.707) with 181 threat-sibling IPs. Geovalidation anomalies indicate potential misreporting. No immediate blocking recommended; monitor for behavioral changes.
---
## Network Ownership & Infrastructure
- Organization: Ahrefs Pte Ltd (SEO analytics platform)
- ASN: 16276 (OVH SAS)
- CIDR Block: 15.235.27.0/24
- Infrastructure Type: CloudCompute (OVH hosting)
- Registration: ARIN, RIR-registered
The IP is part of a cloud compute subnet used by Ahrefs for proxy services, as evidenced by DNS PTR record `proxy-ca013-san72.ahrefs.net`.
---
## Risk Assessment
| Metric | Value | Severity |
|---|---|---|
| Overall Risk Score | 40 | Moderate |
| Provider Score | 0 | Normal |
| Authority Score | 0 | Normal |
| Abuse Confidence | N/A | Not flagged |
| Blacklist Count | 0 | Clean |
Threat Indicators: None detected. IP is not flagged as Tor exit node, known attacker, or spam source.
---
## Geolocation Analysis
- Reported Location: Beauharnois, Quebec, Canada
- Distance Validation: โ VIOLATION DETECTED
- Claimed distance: 6,082 km
- Observed RTT: 22ms
- Minimum possible RTT: 121.6ms
- Conclusion: Reported geolocation implausible; IP likely not physically located in Canada
---
## Neighborhood Analysis
Subnet: 15.235.27.0/24
| Metric | Value |
|---|---|
| Abuse Density | 0.707 (High) |
| Total Siblings | 256 |
| Active Siblings | 223 |
| Threat Siblings | 181 |
| Classification | High Abuse |
Risk Distribution:
- High Risk: 0 IPs
- Medium Risk: 78 IPs
- Low Risk: 22 IPs
The subnet shows elevated abuse density consistent with cloud hosting environments. Multiple IPs in the range (15.235.27.0-4) show risk scores between 25-50.
---
## Network Services & DNS
- Open Ports: None detected (firewalled)
- HTTP Services: None detected
- DNS Records:
- PTR: `proxy-ca013-san72.ahrefs.net`
- Forward Resolution: Confirmed
- CAA Records: Present
- DNSSEC: Valid
No active services detected; IP appears to be a static cloud address without open ports.
---
## Historical Signals (23 Observations)
- DNS Resolution: Consistent ahrefs.net domain resolution
- Subnet Classification: Maintained high_abuse classification (0.707 abuse density) across observations
- Geolocation: Persistent implausibility violations in RTT validation
- Threat Status: No escalation to persistent malicious behavior
---
## Recommended Actions
Firewall Policy:
- Allow with monitoring (no immediate block)
- Consider rate limiting if outbound traffic anomalies detected
- Monitor for C2 communication patterns
Threat Intel Integration:
- Add to watchlist if suspicious outbound connections observed
- Correlate with known Ahrefs infrastructure campaigns
Investigation Priority:
- MEDIUM (monitor subnet behavior)
- No immediate incident response required
---
## Conclusion
15.235.27.72 is a legitimate cloud infrastructure address owned by Ahrefs. The moderate risk score reflects neighborhood abuse density rather than direct malicious activity. Geovalidation anomalies warrant awareness but do not indicate active threat. SOC analysts should monitor for behavioral changes but may treat as low-priority infrastructure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059692 |
| CIDR Block | 15.235.27.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca013-san72.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca013-san72.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 14:56:16 UTC |
| Last Seen | 2026-06-28 13:44:48 UTC |
| Profile Built | 2026-06-29 07:50:58 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.