# IP INTELLIGENCE BRIEFING
Target: 15.235.98.47/32
Classification: Moderate Risk - Cloud Infrastructure
---
## EXECUTIVE SUMMARY
IP 15.235.98.47 is a cloud-hosted address associated with OVH infrastructure and Ahrefs Pte Ltd. The IP demonstrates moderate risk characteristics with no active threat indicators. Subnet analysis reveals elevated abuse density requiring contextual awareness.
---
## RISK ASSESSMENT
| Metric | Value |
|---|---|
| Risk Score | 40 (Moderate) |
| Provider Score | 0 |
| Authority Score | 0 |
| Abuse Confidence | Not Scored |
| Threat Indicators | None Detected |
| Blacklist Count | 0 |
The IP maintains a moderate risk profile with no known malicious activity, Tor exit node association, or known campaign participation.
---
## OWNERSHIP & GEOLOCATION
Network: OVH-CUST-281059698
ASN: 16276 (OVH)
Organization: Dmytro, Ahrefs Pte Ltd
CIDR Block: 15.235.98.0/24
Registered Location: Singapore (CA)
Infrastructure Type: Cloud Compute
NOTE: Geolocation data shows 3000km accuracy radius with geo-plausibility flagged as false. This discrepancy warrants verification against known OVH Singapore data center locations.
---
## NETWORK CHARACTERISTICS
- Classification: Cloud Infrastructure / Hosting
- Connection Type: Firewalled / No Services
- Open Ports: None detected
- TLS Certificate: Not applicable
- DNS Resolution: proxy-ca019-san47.ahrefs.net
- Forward Confirmation: Pending verification
- Email Authentication: No SPF/DMARC records configured
The IP resolves to ares.net domain infrastructure, consistent with search engine analytics services.
---
## THREAT INTELLIGENCE
Current Threat Status: CLEAN
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Known Campaigns: None
- Threat Feeds: None
Temporal Analysis:
- Total Observations: 18
- Threat Persistence Days: 0
- Is Persistently Malicious: No
- Ownership Changes: 0
---
## SUBNET ENVIRONMENT ANALYSIS
Subnet: 15.235.98.0/24
Abuse Density: 0.7188 (Elevated)
Classification: High Abuse
Inherited Risk Score: 28
Total Siblings: 256
Active Siblings: 241
Threat Siblings: 184
Risk Distribution (Sampled 100 Neighbors):
- High Risk: 0
- Medium Risk: 100
- Low Risk: 0
The subnet exhibits elevated abuse density with the majority of addresses showing medium risk scores. This contextual risk should inform defensive posture decisions.
---
## RELATIONSHIP MAPPING
Network Associations:
- Multiple relationships to OVH-CUST-281059698 network block
DNS Associations:
- proxy-ca019-san47.ahrefs.net (17 relationship entries)
No external entity relationships detected beyond network and DNS associations.
---
## OBSERVATION HISTORY
Recent signal observations indicate consistent cloud infrastructure classification. The IP has been observed in cloud compute environments with OVH provider classification. One observation noted inconsistent cloud flagging on 2026-06-20, but subsequent observations confirm cloud hosting classification.
---
## RECOMMENDED ACTIONS
Defensive Posture: Monitor
- No immediate blocking required given clean threat profile
- Monitor for service activation if firewall configuration changes
- Track DNS resolution consistency
Firewall Rules:
- Allow inbound/outbound based on legitimate business requirements
- Consider subnet-level filtering given elevated abuse density
- Monitor for unusual outbound traffic patterns
Investigation Triggers:
- Service activation or port opening
- DNS resolution changes
- Subnet abuse density increases
- Geolocation inconsistencies
---
INTelligence Product: IPDebrief
Report Date: Current
Data Confidence: Moderate (based on observation count and data sufficiency)
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059698 |
| CIDR Block | 15.235.98.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca019-san47.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca019-san47.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 19% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 15:37:58 UTC |
| Last Seen | 2026-06-28 09:02:52 UTC |
| Profile Built | 2026-06-29 03:07:06 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 20 |
Full dossier details are available via our API.