IPDebrief

15.235.98.34

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING: 15.235.98.34/32

## Executive Summary

IP 15.235.98.34 is a cloud infrastructure address hosted by OVH with moderate risk classification (Risk Score: 40). The IP shows no active threat indicators but is associated with a high-abuse-density subnet and exhibits geolocation inconsistencies requiring validation.

---

## Asset Profile

AttributeValue
**IP Address**15.235.98.34/32
**ASN**16276 (OVH)
**Organization**Dmytro, Ahrefs Pte Ltd
**Network**OVH-CUST-281059698
**CIDR Block**15.235.98.0/24
**Infrastructure**CloudCompute (OVH Hosting)
**Reputation**Moderate Risk

---

## Geolocation Analysis

Flagged Anomaly: Significant geolocation inconsistencies detected.

---

## Network Classification

---

## Neighborhood Risk Assessment

Subnet: 15.235.98.0/24

Context: This IP resides in a subnet with elevated abuse activity. While 15.235.98.34 shows no direct threat indicators, the neighborhood context suggests heightened scrutiny is warranted.

---

## Threat Indicators

---

## Observation History

19 observations recorded (as of 2026-06-22). No persistent malicious behavior detected. Threat observation count: 0. The IP has maintained consistent cloud infrastructure classification across observations.

---

## Recommended Actions

Immediate Mitigation

SystemRule
**iptables**`iptables -A INPUT -s 15.235.98.34 -j DROP`
**nftables**`nft add rule inet filter input ip saddr 15.235.98.34 drop`
**nginx**`deny 15.235.98.34;`
**Cloudflare WAF**Block 15.235.98.34 β€” IPDebrief risk score 40
**AWS WAF**Block 15.235.98.34/32

Strategic Considerations

1. Block with caution: Moderate risk score (40) suggests balanced approachβ€”block if receiving malicious traffic patterns

2. Monitor subnet activity: Consider blocking entire /24 if legitimate traffic not verified

3. Validate geolocation: Do not use reported country/region for policy decisions

4. Review DNSBL listings: Investigate why listed on 1 DNSBL; may indicate prior abuse

---

## Intelligence Assessment

This IP represents a moderate-risk cloud infrastructure address with no current active threat indicators. The primary concerns are:

1. Geolocation data is inconsistent and should be treated as unreliable

2. Resides in high-abuse-density subnet requiring contextual monitoring

3. No open services detected (firewalled/no services)

Action Priority: MEDIUM β€” Monitor for malicious activity patterns; implement blocking if threat behavior observed.

---

*Generated by IPDebrief Intelligence Platform*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡¨πŸ‡¦ Canada
Regionβ€”
CitySingapore
Timezoneβ€”
Latitude43.63
Longitude-79.37

🏒 Ownership & Registration

OrganizationDmytro, Ahrefs Pte Ltd
ASNAS16276
Network NameOVH-CUST-281059698
CIDR Block15.235.98.0/24
RIRARIN
CountrySingapore
Abuse Contactβ€”

🌐 DNS Intelligence

PTRproxy-ca019-san34.ahrefs.net
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-ca019-san34.ahrefs.net

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
33%
24
routing
13%
11
services
12%
22
ownership
25%
22
reputation
36%
13
geolocation
32%
23
Overall25%1015
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-07 23:03:46 UTC
Last Seen2026-06-27 00:28:16 UTC
Profile Built2026-06-27 14:41:50 UTC
Data FreshnessLive
Signal Types20
Total Observations26
πŸ” 20 signal types Β· 26 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.