## IP Intelligence Briefing: 15.235.98.161
Executive Summary
IP address 15.235.98.161 is classified as Moderate Risk (risk score: 50) with operational infrastructure on the OVH cloud platform. The IP resolves to a Ahrefs.net hostname but operates in a high-abuse subnet with 178 of 256 sibling IPs flagged as threats. The address is listed on 8 DNSBLs with 2 active listings at high severity.
Network & Ownership Profile
| Attribute | Value |
|---|---|
| **ASN** | 16276 (OVH) |
| **Organization** | Dmytro, Ahrefs Pte Ltd |
| **CIDR Block** | 15.235.98.0/24 |
| **Infrastructure Type** | CloudCompute / Hosting |
| **Network Classification** | OVH-CUST-281059698 |
Geolocation Data
- Country: CA (Canada)
- City: Singapore
- Accuracy Radius: 3000 km
- Geo Consensus: True
- Note: Geographic data shows inconsistency between country code and city designation.
DNS & Service Analysis
- PTR Hostname: proxy-ca019-san161.ahrefs.net
- Domain: ahrefs.net
- Forward Resolution: Confirmed (proxy-ca019-san161.ahrefs.net)
- Open Ports: None detected
- TLS Certificates: None
- HTTP Services: None (Firewalled / No Services)
- DNSSEC Valid: True
Threat Indicators
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0 (network-level)
- DNSBL Listed Count: 2
- Total DNSBL Lists: 8
- Max Severity: High
- Known Campaigns: None identified
Neighborhood Assessment
The /24 subnet (15.235.98.0/24) exhibits high abuse characteristics:
- Abuse Density: 0.6953
- Classification: High Abuse
- Active Siblings: 240 of 256
- Threat Siblings: 178
- Risk Distribution: Medium (100%), High (0%), Low (0%)
Observation History
- Total Observations: 19
- Recent Activity: 2026-06-24 (blacklist listings, DNS resolution)
- Threat Observation Count: 1
- Threat Persistence: Not persistently malicious
- Ownership Changes: 0
- Route Stability: False (0 route changes in 30 days)
Recommended Security Actions
Immediate Firewall Rules:
- iptables: `iptables -A INPUT -s 15.235.98.161 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 15.235.98.161 drop`
- nginx: `deny 15.235.98.161;`
- pfSense: Block 15.235.98.161/32
- Cloudflare WAF: Block with expression `ip.src eq 15.235.98.161`
- AWS WAF: Add 15.235.98.161/32 to IP set
Intelligence Narrative
This IP operates on OVH cloud infrastructure with an Ahrefs.net PTR record, suggesting potential legitimate business use. However, the subnet (15.235.98.0/24) demonstrates high abuse density with 178 threat siblings, indicating compromised infrastructure in the neighborhood. The address carries 2 active DNSBL listings at high severity as of 2026-06-24. While the IP itself lacks open services and shows no known campaign associations, the neighborhood context warrants defensive blocking. The IP is not associated with Tor, spam, or known attacker indicators, but should be blocked due to subnet-level abuse patterns and DNSBL listings.
Recommendation: Block at perimeter firewall, monitor for associated IPs in the same subnet.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059698 |
| CIDR Block | 15.235.98.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca019-san161.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca019-san161.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 23% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-14 07:13:13 UTC |
| Last Seen | 2026-06-28 00:20:35 UTC |
| Profile Built | 2026-06-28 18:25:26 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.