# IP Intelligence Briefing: 15.235.98.103
## Executive Summary
IP 15.235.98.103 is a cloud-hosted infrastructure address associated with OVH provider under organization Dmytro, Ahrefs Pte Ltd (ASN 16276). The address carries a moderate risk score of 40 and resides within a high-abuse subnet (15.235.98.0/24) with an abuse density of 0.582. While the IP resolves to a known infrastructure domain (ahrefs.net), geolocation validation indicates anomalies requiring further scrutiny.
## Technical Profile
- Risk Score: 40 (Moderate Risk)
- ASN: 16276 (OVH)
- Organization: Dmytro, Ahrefs Pte Ltd
- Network Block: 15.235.98.0/24
- Infrastructure Type: CloudCompute (OVH)
- Classification: Cloud hosting with firewall/no services detected
## Geolocation & Validation Concerns
The IP is registered in Canada (CA) but geolocation data indicates Singapore. Reverse DNS resolves to proxy-ca019-san103.ahrefs.net. Geographic validation reveals a critical anomaly: measured RTT of 27ms contradicts the 121.6ms minimum expected for the 6082km distance between reported locations, suggesting potential geolocation spoofing or probe misconfiguration. DNSSEC validation is confirmed, and the IP is listed on 1 of 8 DNSBL lists.
## Neighborhood Analysis
The /24 subnet (15.235.98.0/24) demonstrates elevated abuse characteristics:
- Abuse Density: 0.582 (high abuse classification)
- Total Siblings: 256
- Active Siblings: 222
- Threat Siblings: 149
- Inherited Risk Score: 23
The neighborhood risk distribution shows 99 medium-risk neighbors and 1 low-risk neighbor, with no high-risk neighbors detected alongside the target IP.
## Threat Indicators
- Known Attacker Status: False
- Tor Exit Node: False
- Spam Source: False
- Open Ports: None detected
- HTTP/TLS Services: None detected
- Threat Persistence Days: 0
- Persistently Malicious: False
## Historical Observations
Signal history shows 20 observations across the monitoring period. The most recent activity (2026-06-20) involved CAA record observations for ahrefs.net. Previous observations (2026-06-15) documented the subnet's high-abuse classification and operator score of 0.2174. No persistent malicious behavior has been detected over the observation window.
## Recommended Actions
Based on the risk profile, the following mitigation controls are recommended:
Firewall Rules:
```
iptables -A INPUT -s 15.235.98.103 -j DROP
nft add rule inet filter input ip saddr 15.235.98.103 drop
```
Web Application Firewall:
```
nginx: deny 15.235.98.103;
pfsense: 15.235.98.103/32
```
Cloud WAF Rules:
- Cloudflare WAF: Block with description "IPDebrief risk score 40"
- AWS WAF: Block CIDR 15.235.98.103/32
## Analyst Notes
The moderate risk score of 40 reflects the IP's association with a high-abuse subnet and cloud hosting infrastructure. While no active threat indicators were present during observation, the geographic discrepancy and DNSBL listing warrant monitoring. Consider blocking at perimeter level while correlating with internal telemetry to assess actual traffic patterns from this address.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059698 |
| CIDR Block | 15.235.98.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca019-san103.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca019-san103.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 14:56:16 UTC |
| Last Seen | 2026-06-28 13:47:51 UTC |
| Profile Built | 2026-06-29 07:53:17 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 25 |
Full dossier details are available via our API.