# IP Intelligence Briefing: 15.235.98.224/32
## Executive Summary
IP 15.235.98.224 is a moderate-risk residential proxy endpoint hosted on OVH infrastructure in Singapore (ASN 16276). The IP resolves to aforesaid domain ahrefs.net with PTR hostname proxy-ca019-san224.ahrefs.net. While the IP itself shows no direct threat indicators, it resides within a high-abuse subnet (15.235.98.0/24) with 0.668 abuse density and 171 identified threat siblings.
## Ownership & Infrastructure
- Organization: Dmytro, Ahrefs Pte Ltd
- Netname: OVH-CUST-281059698
- ASN: 16276 (OVH SAS)
- Infrastructure Type: CloudCompute/Hosting
- Geolocation: Singapore (geoPlausible: false; RTT validation violation detected)
- BGP Prefix: 15.235.0.0/17
## Threat Profile
- Risk Score: 40 (Moderate)
- Blacklist Status: Not listed (0 blacklists, 1 DNSBL listing)
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Active Threats: None observed
- Campaign Correlation: None detected
## Network Context
The IP belongs to subnet 15.235.98.0/24 classified as high_abuse. Analysis of 256 sibling IPs reveals:
- Active Siblings: 239
- Threat Siblings: 171 (66.8% abuse density)
- Risk Distribution: 96 medium, 4 low, 0 high risk in sampled neighbors
- Network Classification: Hosting/Cloud provider environment
## DNS Analysis
- PTR Record: proxy-ca019-san224.ahrefs.net
- Forward Resolution: 1 hostname (ahrefs.net)
- Email Authentication: SPF and DMARC not configured
- DNSSEC: Valid
- CAA Records: Present
## Service Enumeration
No open ports or active services detected. The endpoint appears firewalled with no HTTP/HTTPS service banners. TLS certificates not available.
## Historical Observations
24 signal observations recorded. Recent activity (within 24 hours) shows:
- Consistent high-abuse subnet classification
- No ownership changes
- No persistent malicious behavior
- Minimal operator score (0.2174)
## Recommended Actions
Risk-Based Recommendation: Block at perimeter firewall level.
Firewall Rules:
- iptables: `iptables -A INPUT -s 15.235.98.224 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 15.235.98.224 drop`
- nginx: `deny 15.235.98.224;`
- Cloudflare WAF: Block with expression `ip.src eq 15.235.98.224`
- AWS WAF: Add `15.235.98.224/32` to block list
Additional Mitigation: Consider subnet-level blocking for 15.235.98.0/24 given 0.668 abuse density and 171 threat siblings.
## Intelligence Notes
The IP lacks direct malicious indicators but presents elevated contextual risk due to high-abuse neighborhood. The domain ahrefs.net suggests this is a legitimate cloud infrastructure endpoint, though the PTR hostname pattern (proxy-ca019-san224) indicates proxy functionality. No evidence of persistent malicious activity. Block recommendation based on neighborhood risk and conservative risk score of 40.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059698 |
| CIDR Block | 15.235.98.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca019-san224.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca019-san224.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 25% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:46 UTC |
| Last Seen | 2026-06-27 00:26:05 UTC |
| Profile Built | 2026-06-27 14:39:35 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 30 |
Full dossier details are available via our API.