IP Intelligence Briefing: 15.235.98.142
Date: 2026-06-09
---
**1. Core Profile**
- Risk Score: 25 (Low Risk)
- Owner: Dmytro, Ahrefs Pte Ltd (OVH ASN 16276)
- Geolocation:
- Reported Country: Canada (CA)
- City: Singapore (geo-plausibility flag: *False*)
- RTT Anomalies: 30ms RTT inconsistent with 6,082km distance (min possible: 121.6ms).
- Network Role:
- Cloud compute infrastructure (OVH-hosted, no residential/mobile).
- No open services, TLS certs, or HTTP banners detected.
- DNS:
- PTR hostname: `proxy-ca019-san142.ahrefs.net`
- No email auth (SPF/DKIM) or domain hosting detected.
---
**2. Threat & Abuse Context**
- Threat Indicators:
- No malicious indicators, spam, or known attacker associations.
- Subnet Abuse Density: 42.75% (mixed classification).
- Neighboring IPs: 109/255 siblings flagged as high/medium risk.
- Control Plane:
- BGP prefix: `15.235.0.0/17` (OVH).
- DNSSEC valid, CAA records present.
- DNSBL Listings: 1/8 lists (low severity).
---
**3. Temporal Observations**
- First Seen: 2026-06-09 (single observation).
- Geolocation Stability:
- Inconsistent RTT vs. reported location.
- No historical persistence or ownership changes.
---
**4. Relationships & Network**
- Linked Entities:
- Network: OVH-CUST-281059698 (15.235.98.0/24).
- Domain: `ahrefs.net` (DNS hostnames).
- Subnet Risk:
- 109/255 IPs in 15.235.98.0/24 flagged as threats.
- 46% low-risk, 54% medium-risk neighbors.
---
**5. Recommendations**
- Monitor Subnet: Elevated abuse density in 15.235.98.0/24 warrants closer scrutiny.
- Verify Geolocation: Discrepancy between reported location (Canada) and RTT suggests potential spoofing or misconfigured infrastructure.
- DNS Validation: Confirm legitimacy of `proxy-ca019-san142.ahrefs.net` to rule out domain hijacking.
- Baseline Neighbor Activity: Track new threats in the subnet, given mixed risk profile.
Conclusion: While the IP itself is low risk and owned by a legitimate entity, the surrounding subnet exhibits concerning abuse patterns. Further investigation into the subnetβs activity and DNS configuration is advised.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059698 |
| CIDR Block | 15.235.98.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca019-san142.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca019-san142.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 26% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-20 17:47:05 UTC |
| Last Seen | 2026-06-28 12:08:09 UTC |
| Profile Built | 2026-06-29 06:13:42 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.