# IP Intelligence Briefing: 15.235.98.77/32
Date: June 21, 2026 | Classification: Moderate Risk (Score: 40)
## Executive Summary
IP 15.235.98.77 is a cloud-hosted infrastructure address assigned to OVH SAS (AS16276) under organization "Dmytro, Ahrefs Pte Ltd". The IP resolves to Ahrefs.net infrastructure but exhibits geolocation inconsistencies and is listed on one of eight DNS blacklists. While no active attack indicators were observed, the /24 subnet demonstrates high abuse density (76.17%), warranting monitoring for lateral threat activity.
---
## Technical Profile
Ownership & Registration:
- ASN: 16276 (OVH SAS)
- Organization: Dmytro, Ahrefs Pte Ltd
- CIDR Block: 15.235.98.0/24
- Network Classification: CloudCompute / Hosting Infrastructure
DNS Resolution:
- PTR Record: proxy-ca019-san77.ahrefs.net
- Forward Resolution: proxy-ca019-san77.ahrefs.net
- Domain: ahrefs.net
- Forward Confirmation: False
Network Services:
- Open Ports: None detected
- TLS Certificate: None
- HTTP Title: None
- Classification: Firewalled / No Services
---
## Risk Assessment
Threat Indicators:
- Risk Score: 40/100 (Moderate)
- Abuse Confidence: Null
- Blacklist Status: Listed on 1 of 8 DNSBLs
- Known Campaigns: None identified
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Geolocation Discrepancy:
- Claimed Location: Canada (CA)
- Coordinate Location: Singapore (~6,082 km from claimed location)
- RTT Violation: 27ms observed vs. 121.6ms minimum possible for claimed distance
- Validated: False (inconsistent geolocation data)
Control Plane:
- BGP Prefix: 15.235.0.0/17
- Origin ASN: 16276
- Route Stability: False
- DNSSEC Valid: True
---
## Neighborhood Analysis
Subnet: 15.235.98.0/24
- Abuse Density: 76.17% (High Abuse)
- Total Siblings: 256
- Active Siblings: 248
- Threat Siblings: 195
Risk Distribution (Sample of 100 Neighbors):
- High Risk: 0
- Medium Risk: 100
- Low Risk: 0
Key Neighbors:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 15.235.98.0 | 40 | 50 |
| 15.235.98.1 | 50 | 50 |
| 15.235.98.2 | 40 | 50 |
| 15.235.98.3 | 40 | 50 |
| 15.235.98.4 | 40 | 50 |
---
## Observation History
Recent signals (June 21, 2026) indicate:
- Subnet abuse density observed at 76.17%
- Geovalidation failures due to RTT distance violations
- DNS association with ahrefs.net infrastructure
- Pulse detections from AlienVault OTX (3 pulses)
- DNSBL listings with maximum severity: High
---
## Relationship Graph
Primary Associations:
- Network: OVH-CUST-281059698 (26 relationships)
- DNS Hostname: proxy-ca019-san77.ahrefs.net (13 relationships)
---
## Recommendations
Immediate Actions:
1. Monitor inbound/outbound traffic for anomalous patterns from this /24 subnet
2. Review firewall rules to ensure no unauthorized access to Ahrefs.net infrastructure
3. Investigate the 195 threat siblings in the subnet for potential lateral movement
4. Verify legitimate business justification for traffic from this IP
Mitigation:
- No immediate blocking recommended (no active attack indicators)
- Consider enhanced logging for first-hop connections
- Monitor for changes in geolocation patterns or service exposure
SOC Priority: Medium โ Infrastructure hosting requires monitoring but shows no active exploitation indicators.
---
*Generated by IPDebrief Intelligence Platform | Data current as of June 21, 2026*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059698 |
| CIDR Block | 15.235.98.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca019-san77.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca019-san77.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 23% | 1 | 2 |
| geolocation | 34% | 2 | 3 |
| Overall | 24% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-30 17:02:09 UTC |
| Last Seen | 2026-06-29 07:52:34 UTC |
| Profile Built | 2026-06-29 13:53:49 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.