IP Intelligence Briefing: 15.235.96.117
Date: June 12, 2026
---
**1. Core Profile**
- Risk Score: 25 (Low Risk)
- Ownership: Owned by Dmytro, Ahrefs Pte Ltd (OVH ASN 16276).
- Geolocation:
- Country: Canada (CA)
- City: Singapore (potential inconsistency; verify).
- Coordinates: 43.63°N, -79.37°E.
- Network Role:
- Cloud Compute: Hosted by OVH, part of a cloud infrastructure.
- Subnet: 15.235.96.0/24 (OVH-CUST-281059694).
- Threat Indicators:
- No malicious activity detected (no indicators, blacklists, or campaigns).
- DNS: Resolves to `proxy-ca015-san117.ahrefs.net` (Ahrefs domain).
---
**2. Observation History**
- Latest Scan (June 12):
- Subnet abuse density increased to 0.54 (high abuse classification).
- Inherited risk: 21 (moderate).
- Recent Activity (June 1):
- No open ports or TLS certificates detected.
- No HTTP services or banners.
- Stability:
- Route stability: Unstable (fluctuating abuse density).
- No persistent malicious behavior.
---
**3. Network Relationships**
- Shared Network:
- Subnet 15.235.96.0/24 (OVH-CUST-281059694).
- DNS Associations:
- Linked to proxy-ca015-san117.ahrefs.net (Ahrefs domain).
- Organizational Ties:
- Part of OVH infrastructure, associated with Ahrefs.
---
**4. Neighborhood Analysis**
- Subnet: 15.235.96.0/24 (248 total IPs).
- Risk Distribution:
- High Risk: 0 IPs.
- Medium Risk: 40 IPs.
- Low Risk: 58 IPs.
- Abuse Density: 0.3952 (moderate).
- Threat Siblings: 98 IPs flagged as risky.
---
**5. Security Recommendations**
- No Immediate Action Required:
- The IP itself is low-risk with no malicious indicators.
- However, monitor the 15.235.96.0/24 subnet for emerging threats due to moderate abuse density.
- Verify Geolocation:
- Discrepancy between "Canada" and "Singapore" in geolocation data. Investigate for spoofing or misconfiguration.
- DNS Monitoring:
- Track DNS resolution to `proxy-ca015-san117.ahrefs.net` for potential lateral movement or domain hijacking.
---
Conclusion:
15.235.96.117 is a legitimate cloud instance operated by Ahrefs via OVH. While the subnet shows moderate abuse activity, the IP itself is not malicious. SOC teams should focus on monitoring the broader subnet and validating geolocation data. No firewall rules are recommended for this IP unless tied to specific suspicious activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059694 |
| CIDR Block | 15.235.96.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca015-san117.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca015-san117.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 22% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 20% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-30 10:58:06 UTC |
| Last Seen | 2026-06-29 07:29:46 UTC |
| Profile Built | 2026-06-29 07:34:35 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.