IPDebrief

15.235.98.187

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target: 15.235.98.187/32

Classification: Hosting Infrastructure (OVH)

Risk Level: Moderate (Score: 40)

Jurisdiction: Canada (CA)

Generated: 2026-06-28

---

## Executive Summary

IP 15.235.98.187 is a moderate-risk (40) hosting infrastructure IP assigned to OVH (ASN 16276, organization: Dmytro, Ahrefs Pte Ltd). The address resolves to proxy-ca019-san187.ahrefs.net and hosts firewalled services with no open ports. While the IP shows no direct threat indicators, it resides within a high-abuse subnet (15.235.98.0/24) exhibiting 71.48% abuse density and 183 threat-sibling IPs.

---

## Technical Profile

AttributeValue
**IP Address**15.235.98.187/32
**ASN**16276 (OVH)
**Organization**Dmytro, Ahrefs Pte Ltd
**Netname**OVH-CUST-281059698
**CIDR Block**15.235.98.0/24
**Geolocation**Canada (CA)
**Classification**Hosting / Cloud
**DNS Target**proxy-ca019-san187.ahrefs.net
**Open Ports**None detected
**Tor Exit**No
**Known Attacker**No
**Blacklist Count**0

---

## Neighborhood Analysis

Subnet: 15.235.98.0/24

Abuse Density: 0.7148 (High Abuse Classification)

Total Siblings: 256

Active Siblings: 242

Threat Siblings: 183

Inherited Risk: 28

The /24 subnet demonstrates elevated abuse activity with 71.48% of sibling IPs classified as abuse sources. This contextual risk factor warrants defensive consideration despite the target IP's clean direct indicators.

---

## Threat Observation History

Observations indicate stable cloud hosting assignment with consistent OVH provider attribution. No escalation in threat signals observed.

---

## Related Entities

---

## Defensive Actions

Based on risk profile and neighborhood context, the following firewall rules are recommended:

iptables:

```

iptables -A INPUT -s 15.235.98.187 -j DROP

```

nftables:

```

nft add rule inet filter input ip saddr 15.235.98.187 drop

```

nginx:

```

deny 15.235.98.187;

```

Cloudflare WAF:

```json

{

"description": "Block 15.235.98.187 โ€” IPDebrief risk score 40",

"action": "block",

"filter": {

"expression": "ip.src eq 15.235.98.187"

}

}

```

AWS WAF:

```json

{

"Addresses": ["15.235.98.187/32"],

"Description": "IPDebrief risk 40"

}

```

---

## Intelligence Narrative

IP 15.235.98.187 presents moderate-risk hosting infrastructure with clean direct threat indicators. The IP serves as a proxy endpoint for ahrefs.net and is assigned to OVH's cloud hosting services. While the IP itself shows no evidence of malicious activity, the /24 subnet exhibits high abuse density (71.48%) with 183 threat-sibling addresses. This neighborhood context suggests defensive blocking is prudent for high-value targets.

Recommended Action: Implement blocking firewall rules for inbound traffic. Monitor for lateral movement indicators if this IP appears in traffic logs. No immediate threat to infrastructure detected; however, the subnet's abuse classification warrants ongoing monitoring.

---

*Intelligence produced by IPDebrief. All data derived from active network observations and threat intelligence feeds.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡จ๐Ÿ‡ฆ Canada
Regionโ€”
Cityโ€”
Timezoneโ€”
Latitude43.63
Longitude-79.37

๐Ÿข Ownership & Registration

OrganizationDmytro, Ahrefs Pte Ltd
ASNAS16276
Network NameOVH-CUST-281059698
CIDR Block15.235.98.0/24
RIRARIN
CountrySingapore
Abuse Contactโ€”

๐ŸŒ DNS Intelligence

PTRproxy-ca019-san187.ahrefs.net
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-ca019-san187.ahrefs.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 โ€” Basic operator with some routing infrastructure
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
31%
24
routing
27%
23
services
15%
22
ownership
30%
33
reputation
31%
13
geolocation
25%
22
Overall27%1217
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Geo sources disagree on country: US, CA

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-20 11:45:31 UTC
Last Seen2026-06-28 11:36:25 UTC
Profile Built2026-06-29 05:40:28 UTC
Data FreshnessLive
Signal Types25
Total Observations29
๐Ÿ” 25 signal types ยท 29 observations collected
This report is generated from 25+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.