# IP Intelligence Briefing: 15.235.98.85
## Executive Summary
IP 15.235.98.85 is registered to OVH hosting infrastructure (ASN 16276, organization: Dmytro, Ahrefs Pte Ltd) and currently presents a moderate risk score of 40. The IP resolves to aresolvable hostname (proxy-ca019-san85.ahrefs.net) within the ahrefs.net domain. However, multiple geolocation inconsistencies and high-abuse subnet characteristics warrant continued monitoring.
## Network Classification
- Provider: OVH
- Infrastructure Type: Cloud Compute
- CIDR Block: 15.235.98.0/24
- Network Role: Firewalled / No Services
- Cloud Provider: Yes
- DNS Resolved: proxy-ca019-san85.ahrefs.net
## Risk Assessment
Current Risk Score: 40 (Moderate Risk)
Risk Profile:
- No active threat indicators (no known campaigns, not a Tor exit node, not classified as known attacker or spam source)
- Blacklist count: 0
- Control plane delegation shows minimal operator score (0.2174)
- No DNSBL listings observed
Geolocation Anomaly:
- Reported location: Singapore, CA
- Critical Finding: Geolocation implausibility detected. Probe measurements show 27ms RTT, but minimum possible RTT for 6,082km distance is 121.6ms. This indicates the reported geolocation is unreliable.
- geoPlausible flag: false
- 5 probe points with average RTT: 30.6ms
## Subnet Analysis
Subnet: 15.235.98.0/24
- Abuse Density: 0.625 (High)
- Classification: high_abuse
- Total Siblings: 256
- Active Siblings: 229
- Threat Siblings: 160
The IP resides in a subnet with significant abuse activity. Of 256 total sibling IPs, 160 have been identified as threats.
## Observation History
Recent signal observations (June 2026) indicate:
- Consistent high_abuse classification for the /24 subnet
- Persistent RTT/geolocation validation failures
- Multiple control plane assessments showing minimal operator risk
- No persistent malicious threat pattern detected
## Relationships
- 42 total relationships identified
- Primary association: Same Network (OVH-CUST-281059698)
- No cross-organization or cross-network relationships detected
## Recommended Actions
Despite moderate risk classification, the high-abuse subnet context and geolocation inconsistencies support defensive blocking:
```bash
# iptables
iptables -A INPUT -s 15.235.98.85 -j DROP
# nftables
nft add rule inet filter input ip saddr 15.235.98.85 drop
# pfSense
15.235.98.85/32
# Cloudflare WAF
Block 15.235.98.85 โ IPDebrief risk score 40
# AWS WAF
Addresses: ["15.235.98.85/32"]
```
## Intelligence Notes
- IP appears to be part of aresolvable proxy infrastructure for ahrefs.net
- High-abuse subnet context suggests shared infrastructure risk
- Geolocation data should not be relied upon for this IP
- No direct threat indicators present, but subnet-level risk is elevated
---
*Report generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059698 |
| CIDR Block | 15.235.98.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca019-san85.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca019-san85.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 23% | 1 | 2 |
| geolocation | 40% | 2 | 3 |
| Overall | 23% | 10 | 13 |
| Data Coherence | Mixed Signals (60%) โ 2 contradiction(s) |
| Attribution | Very Low (20%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ Geo sources disagree on country: US, CA
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-24 00:31:21 UTC |
| Last Seen | 2026-06-28 23:14:53 UTC |
| Profile Built | 2026-06-29 05:15:30 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.