# IP Intelligence Briefing: 15.235.27.98/32
## Executive Summary
IP 15.235.27.98 presents a moderate risk profile (40/100) associated with OVH cloud infrastructure. The address belongs to the OVH-CUST-281059692 network block, registered under Dmytro, Ahrefs Pte Ltd. While no direct malicious activity has been attributed to this specific IP, the subnet exhibits elevated abuse characteristics warranting monitoring.
## Risk Assessment
- Risk Score: 40/100 (Moderate Risk)
- Provider: OVH (ASN 16276)
- Infrastructure Type: CloudCompute / Hosting
- Geolocation: Listed as Singapore, Canada (CA) โ RTT analysis indicates geolocation validation issues (27ms RTT inconsistent with 6,082km distance)
- DNS Resolution: proxy-ca013-san98.ahrefs.net
- Service Status: No open ports detected โ infrastructure appears firewalled
## Subnet Analysis: 15.235.27.0/24
- Abuse Density: 0.5195 (High Abuse Classification)
- Total Siblings: 256
- Active Siblings: 227
- Threat Siblings: 133
- Inherited Risk: 20
The parent subnet demonstrates significant abuse concentration. 133 of 256 IP addresses in the /24 block have been flagged as threats, indicating potential infrastructure sharing or co-tenancy abuse patterns.
## Historical Observation Timeline
24 signal observations recorded. Key findings:
- June 22, 2026: Cloud infrastructure classification confirmed; DNS resolution to ahrefs.net established
- June 26, 2026: Subnet abuse density signal confirmed at 0.5195
No persistent malicious activity detected. The IP maintains stable cloud hosting characteristics without escalation in threat posture.
## Threat Indicators
- Blacklist Status: 0 blacklists (DNSBL: 1 of 8 lists)
- Known Attacker: False
- Tor Exit Node: False
- Spam Source: False
- Known Campaigns: None
## Infrastructure Relationships
70 relationships identified, predominantly same-network associations to OVH-CUST-281059692. No connections to known malicious campaigns or certificate-based threat indicators.
## Recommended Actions
Based on risk profile and subnet abuse density, the following firewall rules are recommended:
iptables:
```
iptables -A INPUT -s 15.235.27.98 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 15.235.27.98 drop
```
Cloudflare WAF:
```json
{"description":"Block 15.235.27.98 โ IPDebrief risk score 40","action":"block","filter":{"expression":"ip.src eq 15.235.27.98"}}
```
AWS WAF:
```json
{"Addresses":["15.235.27.98/32"],"Description":"IPDebrief risk 40"}
```
## SOC Analyst Notes
This IP should be blocked if the organization maintains conservative posture policies for OVH cloud infrastructure, particularly given the high-abuse density of the parent subnet. The address resolves to a legitimate ahrefs.net domain, suggesting potential use for SEO/traffic analysis services. However, the subnet's 52% threat sibling ratio (133/256) indicates shared infrastructure risks.
Priority: Medium โ Monitor for activity escalation; block if service not recognized.
Correlation Recommendation: Review traffic patterns from this IP against known legitimate ahrefs.net service endpoints to determine if blocking is operationally feasible.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059692 |
| CIDR Block | 15.235.27.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca013-san98.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca013-san98.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:46 UTC |
| Last Seen | 2026-06-27 00:07:30 UTC |
| Profile Built | 2026-06-27 14:21:22 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 28 |
Full dossier details are available via our API.