# IP Intelligence Briefing: 15.235.98.26/32
Classification: Moderate Risk / High Abuse Subnet
Date: 2026-06-26
Risk Score: 50/100
## Executive Summary
IP 15.235.98.26 is a cloud-hosted infrastructure endpoint belonging to OVH network (ASN 16276), organized under Dmytro, Ahrefs Pte Ltd. The IP resolves to proxy-ca019-san26.ahrefs.net and is hosted on cloud infrastructure. Despite the hostname association with Ahrefs, the IP exhibits elevated risk characteristics due to high-abuse subnet classification and multiple DNS blacklist listings.
## Technical Profile
Network Ownership:
- ASN: 16276 (OVH)
- Organization: Dmytro, Ahrefs Pte Ltd
- CIDR: 15.235.98.0/24
- Network Role: Cloud Hosting / No Active Services
- Infrastructure Type: CloudCompute
Geolocation:
- Reported Country: CA (Canada)
- City: Singapore
- RTT Discrepancy: 31ms observed vs. 121.6ms minimum possible for 6,082km distance
- Geo validation flagged as implausible (geoPlausible: false)
DNS Analysis:
- PTR Hostname: proxy-ca019-san26.ahrefs.net
- Forward Resolution: Confirmed to ahrefs.net
- Email Authentication: No SPF, DMARC, or TXT records detected
- DNSBL Listings: 2 out of 8 total blacklist sources
## Threat Indicators
Risk Assessment:
- Risk Score: 50 (Moderate)
- Abuse Confidence: Not scored
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Subnet Context (15.235.98.0/24):
- Abuse Density: 58.98% (High Abuse Classification)
- Total Siblings: 256
- Active Siblings: 248
- Threat Siblings: 151 (58.98%)
- Inherited Risk: 23
## Observation History
Recent Signals (2026-06-26):
- 25 total observations recorded
- Operator Score: Minimal (0.1)
- DNSBL Listed: High severity listings detected
- Infrastructure Classification: Cloud hosting confirmed
- No persistent threat behavior observed
## Related Entities
The IP shares network infrastructure with 64 related relationships, all mapping to OVH-CUST-281059698 network block. No certificate-based or hostname-based correlations beyond the Ahrefs domain family.
## Recommended Actions
Immediate:
- No specific security actions recommended at current risk level
- No open ports or active services detected
Defensive Controls (Recommended for High-Assurance Environments):
- Block at firewall level (iptables, nftables, pfSense)
- Add to Cloudflare WAF blocklist
- Configure AWS WAF rule for 15.235.98.26/32
Monitoring:
- Monitor for new blacklist additions
- Track subnet abuse density changes
- Validate geolocation consistency
## Analyst Notes
This IP presents a moderate-risk profile with significant contextual indicators. The 58.98% abuse density of the /24 subnet warrants heightened scrutiny despite the Ahrefs hostname. The geolocation discrepancy (CA vs Singapore) with implausible RTT values suggests potential proxy usage or misreported metadata. SOC analysts should evaluate traffic patterns from this IP against organizational threat intelligence before applying blocking rules, particularly given the absence of active service signatures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059698 |
| CIDR Block | 15.235.98.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca019-san26.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca019-san26.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 17% | 2 | 3 |
| ownership | 12% | 2 | 2 |
| reputation | 27% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 21% | 10 | 16 |
| Data Coherence | Mixed Signals (60%) โ 2 contradiction(s) |
| Attribution | Very Low (20%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ Geo sources disagree on country: US, CA
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-12 03:42:49 UTC |
| Last Seen | 2026-06-27 20:51:57 UTC |
| Profile Built | 2026-06-28 20:58:19 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 27 |
Full dossier details are available via our API.