# IP INTELLIGENCE BRIEFING: 15.235.98.168/32
## Executive Summary
Target IP 15.235.98.168 is classified as MODERATE RISK (Score: 40/100) and operates within OVH cloud infrastructure. The IP resolves to Ahrefs.net domain infrastructure but exhibits high subnet abuse density (0.543) and inconsistent geolocation reporting. No active threat indicators detected.
## Ownership & Infrastructure
- ASN: 16276 (OVH SAS)
- Organization: Dmytro, Ahrefs Pte Ltd
- CIDR Block: 15.235.98.0/24
- Infrastructure Type: CloudCompute (OVH hosting)
- Network Classification: Firewalled / No Services Detected
## Geolocation Analysis
CONFLICTING GEOLOCATION DATA โ Multiple data sources report inconsistent locations:
- Primary consensus: Singapore (CA region)
- Historical observations: Canada (CA), United States (US)
- Accuracy Radius: 3,000 km
- Geo-Plausibility: FALSE
This inconsistency warrants monitoring for potential reputation manipulation or infrastructure migration.
## DNS & Resolution
- PTR Hostname: proxy-ca019-san168.ahrefs.net
- Resolved Domain: ahrefs.net
- Forward Resolution: 1 record confirmed
- DNSSEC: Valid
- CAA Records: Present
- DNSBL Listings: 8 total lists (1 confirmed listing)
## Threat Indicators
- Known Attacker: FALSE
- Tor Exit Node: FALSE
- Spam Source: FALSE
- Campaign Associations: None detected
- Abuse Confidence Score: Not scored
- Threat Feeds: Clean
## Network Neighborhood Analysis
SUBNET: 15.235.98.0/24 โ HIGH ABUSE DENSITY
- Abuse Density: 0.543 (Elevated)
- Active Siblings: 222/256
- Threat Siblings: 139 (62.6% of active IPs)
- Risk Distribution: 99 medium-risk, 1 low-risk, 0 high-risk
The subnet exhibits elevated abuse characteristics. This IP benefits from shared infrastructure reputation but should be evaluated within subnet context.
## Control Plane & Routing
- BGP Prefix: 15.235.0.0/17
- Route Stability: FALSE (Route changes detected in 30-day window)
- RPKI State: Not verified
- DNSSEC: Valid
- Operator Score: 0.2174 (Minimal)
## Temporal Observations
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 1
- Persistently Malicious: FALSE
## Historical Trends (Last 20 Observations)
Recent signal history indicates:
- Geolocation instability (CA/US/Singapore conflicts)
- Multiple threat feed associations detected on 2026-06-15
- Consistent network classification as high-abuse subnet
- Operator score remained stable at 0.2174
## Recommended Actions
1. MONITOR โ No immediate blocking required; IP associated with legitimate Ahrefs infrastructure
2. SUBNET CONTEXT โ Evaluate traffic patterns against subnet 15.235.98.0/24 abuse density
3. GEOLOCATION VALIDATION โ Verify actual deployment location; inconsistent reporting may indicate infrastructure changes
4. DNSBL MONITORING โ Track DNSBL listing status (8 total lists, 1 active)
## Intelligence Conclusion
Target IP represents cloud infrastructure for Ahrefs (SEO analytics platform) with no direct malicious indicators. However, the high-abuse subnet environment and geolocation inconsistencies warrant continued monitoring. No firewall rules recommended at this time; maintain traffic logs for behavioral analysis.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059698 |
| CIDR Block | 15.235.98.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca019-san168.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca019-san168.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 09:23:34 UTC |
| Last Seen | 2026-06-28 06:53:31 UTC |
| Profile Built | 2026-06-29 00:59:12 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.