# IP Intelligence Briefing: 15.235.98.162/32
Date: 2026-06-22
Classification: Moderate Risk / Hosting Infrastructure
Risk Score: 40/100
---
## Executive Summary
IP 15.235.98.162 is a cloud-based hosting infrastructure address associated with OVH SAS (ASN 16276) and registered to Dmytro, Ahrefs Pte Ltd. The IP exhibits moderate risk characteristics with a risk score of 40. While the IP itself shows no direct threat indicators, it resides within a high-abuse density subnet (15.235.98.0/24) with an abuse density of 0.6562 and 168 threat siblings out of 239 active neighbors.
---
## Ownership and Network Classification
| Attribute | Value |
|---|---|
| ASN | 16276 |
| Organization | Dmytro, Ahrefs Pte Ltd |
| Netname | OVH-CUST-281059698 |
| Provider | OVH |
| Infrastructure Type | CloudCompute |
| Classification | Hosting Provider |
| CIDR Block | 15.235.98.0/24 |
Note: Geolocation data indicates Singapore (CA) but displays significant validation anomalies with RTT measurements inconsistent with claimed distance (27ms observed vs 121.6ms minimum possible for 6082km), suggesting potential geolocation spoofing or data inaccuracies.
---
## Network and Subnet Analysis
The 15.235.98.0/24 subnet demonstrates elevated abuse characteristics:
- Abuse Density: 0.6562 (high)
- Total Siblings: 256
- Active Siblings: 239
- Threat Siblings: 168
- Inherited Risk Score: 26
Neighboring IP risk distribution within the /24 subnet shows 100 medium-risk neighbors and zero high-risk or low-risk endpoints. Representative neighbors include 15.235.98.0 (risk 40), 15.235.98.1 (risk 50), and 15.235.98.2 (risk 50).
---
## DNS and Service Profile
- PTR Hostname: proxy-ca019-san162.ahrefs.net
- Forward Resolution: proxy-ca019-san162.ahrefs.net
- Domain Association: ahrefs.net
- Forward Resolution Count: 1
- Open Ports: None detected (firewalled/no services)
- HTTPS/TLS: No certificates detected
- Email Authentication: No SPF or DMARC records configured
The absence of open ports and services suggests this IP is either intentionally firewalled or represents a backend infrastructure endpoint without public-facing services.
---
## Threat and Control Plane Assessment
- Abuse Confidence Score: Not reported
- Blacklist Count: 0
- Known Tor Exit/Attacker/Spam Source: False
- DNSBL Listed: 1/8 total lists
- Operator Score: 0.2174 (Minimal)
- Route Stability: False
- BGP Prefix: 15.235.0.0/17
- Threat Persistence Days: 0
No active threat indicators were detected. The IP shows no correlation to known campaigns, attacker tooling, or malicious infrastructure markers.
---
## Historical Observations
The IP has been observed 23 times across multiple signal categories between June 17-22, 2026:
- June 22, 2026: Cloud infrastructure classification (confidence 0.90)
- June 18, 2026: High abuse subnet classification (confidence 0.75), operator score validation (confidence 0.60)
- June 17, 2026: Geolocation validation anomalies detected
The temporal profile indicates persistent presence without significant reputation degradation or escalation. No ownership changes recorded.
---
## Recommended Actions
Based on the moderate risk score (40) and subnet-level abuse context, the following actions are recommended:
| Platform | Action |
|---|---|
| iptables | `iptables -A INPUT -s 15.235.98.162 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 15.235.98.162 drop` |
| nginx | `deny 15.235.98.162;` |
| pfSense | `15.235.98.162/32` |
| Cloudflare WAF | Block with description: "IPDebrief risk score 40" |
| AWS WAF | Add address: 15.235.98.162/32 with description "IPDebrief risk 40" |
Recommendation: Given the lack of direct threat indicators and the presence of services/firewalling, consider a block action with monitoring rather than immediate takedown. The subnet-level abuse density warrants blocking this IP to prevent potential lateral movement or abuse of the hosting infrastructure.
---
## Conclusion
IP 15.235.98.162 represents a moderate-risk hosting infrastructure endpoint with no direct malicious indicators but elevated neighborhood risk. The subnet classification as "high_abuse" with 168 threat siblings suggests defensive blocking is warranted. Continuous monitoring recommended for related IPs within the 15.235.98.0/24 block.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059698 |
| CIDR Block | 15.235.98.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca019-san162.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca019-san162.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:46 UTC |
| Last Seen | 2026-06-27 00:22:34 UTC |
| Profile Built | 2026-06-27 14:36:06 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 27 |
Full dossier details are available via our API.