IPDebrief

15.235.96.102

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# INTELLIGENCE BRIEFING: 15.235.96.102

Classification: Moderate Risk / High-Abuse Subnet Context

Date: 2026-06-21

Prepared For: SOC Operations

---

## EXECUTIVE SUMMARY

IP 15.235.96.102 presents a moderate risk profile (Risk Score: 50) within a high-abuse subnet environment. The address resolves to a hostname associated with ahrefs.net infrastructure but operates within an OVH cloud compute environment showing significant neighborhood threat concentration.

---

## OWNERSHIP & INFRASTRUCTURE

Provider: OVH (ASN 16276)

Network: OVH-CUST-281059694 (15.235.96.0/24)

Infrastructure Type: Cloud Compute

Registration: Dmytro, Ahrefs Pte Ltd

The IP is hosted on OVH cloud infrastructure. DNS resolution confirms association with `proxy-ca015-san102.ahrefs.net`, indicating legitimate business infrastructure for the SEO marketing platform ahrefs.net.

---

## GEOLOCATION ANOMALIES

Reported Location: Singapore (CA)

Validation Status: GEOLOCATION VIOLATION DETECTED

Analysis indicates significant geolocation inconsistency:

This suggests the IP may be misreported or operating from an unexpected location.

---

## THREAT INTELLIGENCE

Abuse Confidence: Listed on 2 of 8 DNS blacklists (high severity)

Threat Indicators: None directly attributed to this specific IP

Campaign Association: No known campaigns correlated

Critical Finding: While this IP shows no direct threat indicators, the subnet context is highly concerning:

---

## NETWORK CLASSIFICATION

AttributeValue
Cloud InfrastructureYES
CDNNO
VPN/ProxyNO
Tor Exit NodeNO
ResidentialNO
MobileNO
Open ServicesNONE

No active services detected on the IP. No open ports observed.

---

## OBSERVATION HISTORY

19 signal observations recorded across the analysis period. Key temporal findings:

---

## SUBNET ANALYSIS

CIDR: 15.235.96.0/24

Total Siblings: 256

Active Siblings: 210

Threat Siblings: 171

Abuse Classification: HIGH_ABUSE

This represents a 81.4% threat concentration rate within the active subset of the subnet.

---

## RECOMMENDED ACTIONS

Immediate: Block traffic at perimeter controls

```

iptables: iptables -A INPUT -s 15.235.96.102 -j DROP

nftables: nft add rule inet filter input ip saddr 15.235.96.102 drop

Cloudflare WAF: Block 15.235.96.102 (risk score 50)

AWS WAF: Add 15.235.96.102/32 to blocklist

```

Subnet-Level Consideration: Given the 66.8% abuse density of the /24 subnet, consider evaluating blocking rules for the entire 15.235.96.0/24 CIDR block or implementing rate limiting policies.

---

## INTELLIGENCE GAP ASSESSMENT

MetricStatusNotes
Direct ThreatLOWNo direct indicators
Subnet RiskHIGH81.4% threat concentration
GeolocationFLAGGEDSignificant inconsistency
DNS ReputationMODERATE2/8 blacklist listings
Service ExposureLOWNo open ports

---

ANALYSIS: The IP requires blocking due to neighborhood context, despite lack of direct threat indicators. The subnet's high abuse density and significant threat concentration suggest this address may be part of a compromised or misconfigured cloud infrastructure block. Monitor for additional sightings from related ahrefs.net hostnames within the same subnet.

END OF BRIEFING

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡จ๐Ÿ‡ฆ Canada
Regionโ€”
CitySingapore
Timezoneโ€”
Latitude43.63
Longitude-79.37

๐Ÿข Ownership & Registration

OrganizationDmytro, Ahrefs Pte Ltd
ASNAS16276
Network NameOVH-CUST-281059694
CIDR Block15.235.96.0/24
RIRARIN
CountrySingapore
Abuse Contactโ€”

๐ŸŒ DNS Intelligence

PTRproxy-ca015-san102.ahrefs.net
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-ca015-san102.ahrefs.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
33%
24
routing
13%
11
services
13%
11
ownership
19%
22
reputation
22%
13
geolocation
24%
23
Overall21%914
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Claimed geolocation contradicts RTT physics measurement

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-30 06:21:59 UTC
Last Seen2026-06-29 07:11:09 UTC
Profile Built2026-06-29 07:17:06 UTC
Data FreshnessLive
Signal Types19
Total Observations20
๐Ÿ” 19 signal types ยท 20 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.