# IPDebrief Intelligence Briefing: 15.235.96.10/32
## Executive Summary
IP 15.235.96.10 is classified as Moderate Risk (Risk Score: 40) with infrastructure hosted on OVH CloudCompute infrastructure. The IP resolves to ahostname associated with ahrefs.net and operates in a high-abuse subnet environment. No active threat indicators were observed, but the subnet shows elevated abuse density.
## Infrastructure Profile
- Organization: Dmytro, Ahrefs Pte Ltd (AS16276)
- Network Block: 15.235.96.0/24 (OVH-CUST-281059694)
- Provider: OVH (CloudCompute, Hosting services enabled)
- Geolocation: Reported Singapore (CA), but geo-validation flags RTT inconsistency (26ms vs 121.6ms minimum for 6,082km distance)
- DNS Resolution: proxy-ca015-san10.ahrefs.net (ahrefs.net)
- Services: Firewalled / No Services detected
- Route Stability: Unstable (route changes observed in last 30 days)
## Threat Assessment
- Abuse Confidence Score: Not available
- Blacklist Status: 0 direct blacklists
- DNSBL Listed: 1 of 8 total lists
- Tor Exit: No
- Known Attacker: No
- Spam Source: No
- Campaign Association: None identified
## Neighborhood Analysis
The /24 subnet 15.235.96.0/24 exhibits high abuse density (0.6992):
- Total Subnet Capacity: 256 IPs
- Active IPs: 218 (85.2% utilization)
- Threat IPs: 179 (82.1% of active)
- Risk Distribution: 0 high-risk, 83 medium-risk, 17 low-risk
This indicates the IP operates in a high-abuse cloud infrastructure environment, though the IP itself shows no direct threat indicators.
## Observed Behavior
Analysis of 21 historical observations (June 2026) shows:
- Consistent DNS resolution to ahrefs.net domain
- Persistent high-abuse subnet classification
- Geolocation inconsistencies across multiple sources
- No evidence of malicious activity escalation
## Recommended Actions
While no explicit threat indicators were detected, the moderate risk score and high-abuse neighborhood suggest defensive posture. Recommended firewall rules:
- iptables: `iptables -A INPUT -s 15.235.96.10 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 15.235.96.10 drop`
- nginx: `deny 15.235.96.10;`
- pfSense: `15.235.96.10/32`
- Cloudflare WAF: Block with expression `ip.src eq 15.235.96.10`
- AWS WAF: Address `15.235.96.10/32`
Note: These recommendations are probabilistic. Combine with additional signals before enforcement.
## Intelligence Conclusion
IP 15.235.96.10 represents a moderate risk cloud infrastructure endpoint with no direct malicious activity but operating in a high-abuse environment. The ahrefs.net association suggests legitimate hosting use, but the subnet's abuse density warrants monitoring. No immediate blocking required unless additional threat signals emerge.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059694 |
| CIDR Block | 15.235.96.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca015-san10.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca015-san10.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 22% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 22% | 10 | 13 |
| Data Coherence | Mixed Signals (60%) โ 2 contradiction(s) |
| Attribution | Very Low (20%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ Geo sources disagree on country: US, CA
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-25 12:41:35 UTC |
| Last Seen | 2026-06-29 01:31:56 UTC |
| Profile Built | 2026-06-29 13:35:31 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.