IPDebrief

15.235.98.137

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Subject: 15.235.98.137/32

Classification: Moderate Risk

Date: Current Intelligence Cycle

Prepared For: SOC Operations Team

---

## EXECUTIVE SUMMARY

IP address 15.235.98.137 is a Canadian-resident OVH-hosted endpoint associated with the Ahrefs infrastructure. The IP carries a moderate risk score of 40, with no current active threat indicators. However, the subnet 15.235.98.0/24 exhibits high abuse density, with 166 threat-identified siblings out of 256 total IPs (65% threat rate). This IP was observed as firewalled with no active services.

---

## OWNERSHIP AND NETWORK CLASSIFICATION

AttributeValue
ASNAS16276 (OVH SAS)
OrganizationDmytro, Ahrefs Pte Ltd
Network NameOVH-CUST-281059698
Registration RIRARIN
Geographic LocationBeauharnois, QC, Canada
Geolocation ConsensusVerified

The IP is hosted on OVH infrastructure and resolves to proxy-ca019-san137.ahrefs.net, indicating legitimate association with Ahrefs, a known SEO analytics provider.

---

## RISK ASSESSMENT

Current Risk Score: 40 (Moderate Risk)

Risk Indicators:

Security Posture: The IP presents minimal immediate threat, but operates within a high-abuse subnet environment that warrants monitoring.

---

## NEIGHBORHOOD ANALYSIS

Subnet: 15.235.98.0/24

Risk Distribution in Subnet:

The subnet demonstrates significant abuse activity concentration. The target IP's inherited risk score is elevated to 25 due to neighborhood context, despite individual moderate scoring.

---

## OBSERVATION HISTORY

Total Historical Signals: 28

Key Historical Events:

Temporal Analysis: The IP shows no persistent malicious behavior patterns. Threat observation count is limited (1), with no evidence of sustained malicious activity.

---

## TECHNICAL PROFILE

CategoryStatus
Open PortsNone detected
TLS CertificateNone
HTTP ServicesNone
Reverse DNSproxy-ca019-san137.ahrefs.net
Forward ResolutionConfirmed (1 hostname)
Service ClassificationFirewalled / No Services
Email ReputationNot scored

---

## NETWORK CONTROL PLANE

---

## RECOMMENDED ACTIONS

For SOC/Defense Teams:

1. Monitor but Do Not Block: Current risk profile does not warrant immediate blocking. The IP is associated with legitimate infrastructure (Ahrefs).

2. Subnet Awareness: Monitor all traffic from 15.235.98.0/24 subnet due to 65% threat sibling rate. Consider implementing subnet-level monitoring rules.

3. Geolocation Discrepancy Note: One historical signal indicates US-based geolocation (Alienvault OTX) conflicting with current Canada profile. This may indicate IP reuse or infrastructure changes.

4. DNSBL Verification: Confirm current DNSBL listing status. Single listing is of low concern but warrants periodic verification.

5. Service Monitoring: IP is currently firewalled with no open services. Maintain awareness of any service changes that could alter risk profile.

---

## CONCLUSION

IP 15.235.98.137 presents a moderate risk profile with no immediate threat indicators. The primary concern is the high abuse density of its parent subnet. SOC teams should monitor the subnet for emerging threats while maintaining awareness of the IP's legitimate Ahrefs association. No immediate defensive action is required, but the subnet should be flagged for enhanced monitoring.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡จ๐Ÿ‡ฆ Canada
RegionQC
CityBeauharnois
Timezoneโ€”
Latitude43.63
Longitude-79.37

๐Ÿข Ownership & Registration

OrganizationDmytro, Ahrefs Pte Ltd
ASNAS16276
Network NameOVH-CUST-281059698
CIDR Block15.235.98.0/24
RIRARIN
CountrySingapore
Abuse Contactโ€”

๐ŸŒ DNS Intelligence

PTRproxy-ca019-san137.ahrefs.net
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-ca019-san137.ahrefs.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
26%
24
routing
13%
11
services
12%
22
ownership
15%
22
reputation
28%
13
geolocation
35%
23
Overall22%1015
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Claimed geolocation contradicts RTT physics measurement

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-07 23:03:46 UTC
Last Seen2026-06-27 00:21:04 UTC
Profile Built2026-06-27 14:33:53 UTC
Data FreshnessLive
Signal Types23
Total Observations29
๐Ÿ” 23 signal types ยท 29 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.