IPDebrief

15.235.98.189

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IPDEBRIEF THREAT INTELLIGENCE BRIEFING

Target IP: 15.235.98.189/32

Report Date: 2026-06-17

Classification: Moderate Risk (Score: 40)

Status: Active Threat Signal Observed

---

## EXECUTIVE SUMMARY

IP 15.235.98.189 is a cloud-compute host associated with OVH infrastructure (ASN 16276) under the Ahrefs organization. The IP presents moderate risk with significant contextual indicators warranting defensive blocking. The IP's /24 subnet demonstrates high abuse density (0.6484), with 166 of 239 active sibling IPs flagged as threats. Geo-location data contains validation anomalies.

---

## OWNERSHIP & INFRASTRUCTURE

Provider: OVH (AS16276)

Organization: Dmytro, Ahrefs Pte Ltd

Network Block: 15.235.98.0/24 (OVH-CUST-281059698)

Infrastructure Type: Cloud Compute / Hosting

Network Role: Firewalled / No Services Detected

The IP resolves to DNS hostname `proxy-ca019-san189.ahrefs.net` with forward confirmation failure. No open ports or TLS certificates observed, indicating the system is firewalled.

---

## GEOLOCATION ANOMALIES

Claimed Location: Singapore (CA)

Validation Status: FAILED

Anomaly: RTT violation detected

Network probe data indicates a 6082km distance from probe location with only 28ms average RTT. This violates the minimum possible RTT of 121.6ms for that distance, indicating geolocation spoofing or data inaccuracy. Five probes were conducted with inconsistent results (geoPlausible: false, geoConsensus: false, geoPlausible: false).

---

## THREAT INDICATORS

Risk Score: 40 (Moderate)

Abuse Confidence Score: Not Reported

Blacklist Status: Listed on 1 of 8 DNSBLs

Known Attacker Status: No

Tor Exit Node: No

Campaign Association: None

Recent Signals (24 observations):

---

## NETWORK CONTEXT

Subnet Analysis: 15.235.98.0/24

Risk Distribution in Neighborhood:

The subnet exhibits elevated abuse characteristics with approximately 64.8% of active IPs flagged as threats.

---

## RECOMMENDED ACTIONS

Risk-Based Recommendation: BLOCK

Firewall Rules (Ready for Deployment):

```bash

# iptables

iptables -A INPUT -s 15.235.98.189 -j DROP

# nftables

nft add rule inet filter input ip saddr 15.235.98.189 drop

# nginx

deny 15.235.98.189;

# pfSense

15.235.98.189/32

# Cloudflare WAF

{"description":"Block 15.235.98.189 โ€” IPDebrief risk score 40","action":"block","filter":{"expression":"ip.src eq 15.235.98.189"}}

# AWS WAF

{"Addresses":["15.235.98.189/32"],"Description":"IPDebrief risk 40"}

```

Additional Context:

---

## ANALYST NOTES

1. Infrastructure Legitimacy: IP is associated with Ahrefs, a legitimate SEO analytics company. However, the cloud hosting environment shows abuse indicators.

2. Subnet Risk: The /24 subnet is classified as high-abuse with 65% threat density. Consider implementing subnet-level controls.

3. Geolocation Spoofing: Invalid RTT data suggests infrastructure misconfiguration or malicious activity.

4. Historical Activity: 24 observations recorded with recent threat signals detected.

5. Action Threshold: Risk score of 40 with high-abuse context supports blocking recommendation.

---

END OF BRIEFING

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡จ๐Ÿ‡ฆ Canada
Regionโ€”
CitySingapore
Timezoneโ€”
Latitude43.63
Longitude-79.37

๐Ÿข Ownership & Registration

OrganizationDmytro, Ahrefs Pte Ltd
ASNAS16276
Network NameOVH-CUST-281059698
CIDR Block15.235.98.0/24
RIRARIN
CountrySingapore
Abuse Contactโ€”

๐ŸŒ DNS Intelligence

PTRproxy-ca019-san189.ahrefs.net
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-ca019-san189.ahrefs.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
26%
24
routing
13%
11
services
20%
23
ownership
15%
22
reputation
28%
13
geolocation
35%
23
Overall23%1016
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Claimed geolocation contradicts RTT physics measurement

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-07 23:03:46 UTC
Last Seen2026-06-27 00:23:45 UTC
Profile Built2026-06-27 14:37:15 UTC
Data FreshnessLive
Signal Types21
Total Observations28
๐Ÿ” 21 signal types ยท 28 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.