# INTELLIGENCE BRIEFING: 15.235.98.134/32
## Executive Summary
IP 15.235.98.134 is a moderate-risk (score: 50) cloud infrastructure asset hosted by OVH in Beauharnois, QC (CA). The IP resolves to a proxy hostname under the ahrefs.net domain. While the specific IP shows no active threat indicators, it resides within a high-abuse-density subnet (15.235.98.0/24) where 65% of active siblings exhibit malicious activity. Recommended action: Block at perimeter, monitor for lateral movement.
## Infrastructure Profile
- Organization: Dmytro, Ahrefs Pte Ltd
- ASN: 16276 (OVH SAS)
- CIDR Block: 15.235.98.0/24
- Registration: Afnir (ARIN)
- Infrastructure Type: Cloud compute, hosting provider
- Services: No open ports detected (firewalled/no services)
## Geographic Intelligence
- Location: Beauharnois, Quebec, Canada
- GeoValidation: Discrepancy detectedβprobed distance (6,082 km) inconsistent with reported CA location
- RTT: 29.8ms average (minimum possible for distance: 121.6ms)
## Threat Indicators
- Risk Score: 50/100 (Moderate Risk)
- Blacklist Status: Listed on 2 of 8 DNSBLs
- Tor/VPN/Proxy: Not detected
- Known Attacker: False
- Campaign Association: None identified
- Threat Feeds: Empty
## Domain Resolution
- PTR Hostname: proxy-ca019-san134.ahrefs.net
- Domain: ahrefs.net
- Forward Resolution: Confirmed (1 hostname)
- Email Auth: No SPF/DMARC records detected
## Neighborhood Analysis
- Subnet: 15.235.98.0/24
- Abuse Density: 0.6562 (High)
- Active Siblings: 248/256
- Threat Siblings: 168 (68% of active addresses)
- Risk Distribution: 0 high, 100 medium, 0 low
- Inherited Risk: 26/100
## Historical Observations
- Total Observations: 27
- Observation Period: 2026-06-22 to 2026-06-26 (5-day window)
- Ownership Changes: None
- Threat Persistence: 0 days
- Notable Signals:
- 2026-06-26: Operator score 0.087 (Minimal)
- 2026-06-22: ASN AS16276 OVH SAS identified
- 2026-06-22: ahrefs.net domain confirmed
## Relationship Graph
- Total Relationships: 67
- Primary Link Type: Same Network (OVH-CUST-281059698)
- Network Classification: Multiple same-network associations to OVH customer subnet
## Recommended Security Actions
Firewall Rules
```bash
# iptables
iptables -A INPUT -s 15.235.98.134 -j DROP
# nftables
nft add rule inet filter input ip saddr 15.235.98.134 drop
# nginx
deny 15.235.98.134;
# pfSense
15.235.98.134/32
```
Cloud/WAF Rules
- Cloudflare WAF: Block IP with expression `ip.src eq 15.235.98.134`
- AWS WAF: Add address `15.235.98.134/32` with description "IPDebrief risk 50"
## Analyst Assessment
This IP represents a legitimate cloud hosting asset (OVH) resolving to ahrefs.net proxy infrastructure. The moderate risk score derives primarily from subnet-level abuse indicators rather than IP-specific malicious activity. The high-abuse-density neighborhood (168 threat siblings) warrants defensive posture. No immediate threat indicators present for this specific IP, but perimeter blocking is recommended given the neighborhood context. Monitor for any changes in DNS resolution patterns or emergence of open services.
Priority: Medium
Recommended Action: Block at perimeter firewall; monitor for lateral movement indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059698 |
| CIDR Block | 15.235.98.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca019-san134.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca019-san134.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Mixed Signals (60%) β 2 contradiction(s) |
| Attribution | Very Low (20%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
β Geo sources disagree on country: US, CA
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:46 UTC |
| Last Seen | 2026-06-27 00:20:54 UTC |
| Profile Built | 2026-06-27 14:33:53 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 29 |
Full dossier details are available via our API.