IP Intelligence Briefing: 15.235.27.83
*Generated via IPDebrief Analysis*
---
**1. Core Profile**
- Risk Assessment:
- Risk Score: 25 (Low Risk)
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
- Ownership:
- ASN: AS16276 (OVH)
- Organization: Ahrefs Pte Ltd (OVH-CUST-281059692)
- Geolocation: Singapore (CA), with mixed geolocation data (some records indicate US).
- Threat Indicators:
- No malicious indicators, spam, or known attacker activity.
- DNS: Linked to `proxy-ca013-san83.ahrefs.net` (PTR record).
---
**2. Network Behavior**
- Hosting Role:
- Identified as a cloud compute resource (OVH infrastructure).
- No evidence of CDN,VPN, Tor, or residential traffic.
- Subnet Analysis:
- Subnet: `15.235.27.0/24`
- Abuse Density: 41.27% (moderate risk).
- Neighbor Risk: 104/252 IPs in subnet flagged as threats.
- Active Siblings: 107 IPs (32% of subnet).
---
**3. Historical Observations (Last 30 Days)**
- Persistent Classification:
- Consistently labeled as cloud hosting (OVH).
- Geolocation Variability: Mixed data (some records show US, others CA).
- Threat Trends:
- No escalation in threat signals.
- DNS Stability: Single PTR record (`proxy-ca013-san83.ahrefs.net`) observed.
---
**4. Relationships & Dependencies**
- Network Relationships:
- Same Network: Linked to OVH-CUST-281059692 (252 IPs).
- DNS Associations:
- Directly tied to `proxy-ca013-san83.ahrefs.net` (Ahrefs).
- Technical Context:
- TLS/Services: No open ports or TLS certificates detected.
- Email: No SPF/DKIM records or email-related threats.
---
**5. Recommendations**
- Monitoring:
- Track the `15.235.27.0/24` subnet for emerging threats due to 41% abuse density.
- Validate geolocation anomalies (CA vs. US records).
- Firewall:
- Consider allowing traffic only from trusted sources, given the hosting role.
- Monitor DNS queries to `proxy-ca013-san83.ahrefs.net` for unusual patterns.
---
Conclusion:
The IP is part of a low-risk OVH-hosted cloud infrastructure, likely used for Ahrefs services. While no direct malicious activity is detected, the subnetβs moderate abuse density and mixed geolocation data warrant further investigation. SOC teams should focus on subnet-level monitoring and validate DNS relationships.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059692 |
| CIDR Block | 15.235.27.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca013-san83.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca013-san83.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 20% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-21 14:56:16 UTC |
| Last Seen | 2026-06-28 13:44:30 UTC |
| Profile Built | 2026-06-29 07:50:58 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.