# THREAT INTELLIGENCE BRIEFING: 15.235.96.136/32
Date: 2026-06-28
Risk Level: Moderate Risk (Score: 40/100)
Classification: Cloud Hosting Infrastructure
## Executive Summary
IP 15.235.96.136 is a cloud hosting IP address operated by OVH (ASN 16276) on behalf of Ahrefs Pte Ltd. The address resolved to a hostname proxy-ca015-san136.ahrefs.net and is associated with the domain ahrefs.net. No active threat indicators or known campaigns were observed. The IP exhibits moderate risk characteristics consistent with commercial cloud hosting environments.
## Technical Profile
- Organization: Dmytro, Ahrefs Pte Ltd
- Network Block: 15.235.96.0/24 (OVH-CUST-281059694)
- Infrastructure Type: CloudCompute (OVH provider)
- Geolocation: Canada (QC, Beauharnois)
- DNS: Forward resolution confirmed to proxy-ca015-san136.ahrefs.net
- Services: No open ports detected; firewall or no services exposed
## Risk Assessment
The IP received a risk score of 40/100, classified as Moderate Risk. Control plane analysis indicated DNSBL listing on 1 of 8 threat lists. No evidence of Tor exit node, VPN, proxy, or known attacker behavior. No active threat indicators, blacklist hits beyond DNSBL, or campaign associations were identified.
## Neighborhood Context
The /24 subnet (15.235.96.0/24) exhibits high abuse density at 0.7031 (70.31%), with 180 of 256 total siblings flagged as threats. All sampled neighbors showed medium risk classification (score: 40). This pattern indicates a shared cloud hosting environment where legitimate infrastructure coexists with potentially compromised hosts.
## Observation History
Twenty-two signal observations recorded since 2026-06-20. Recent signals consistently show cloud infrastructure classification with OVH provider. No ownership changes or persistent malicious behavior detected. Threat persistence days: 0.
## Geolocation Validation
RTT-based validation discrepancy noted: Reported location (Canada) showed minimum possible RTT of 121.6ms for 6082km distance, while observed RTT was 27.0ms. This suggests routing anomalies or geolocation data inconsistency rather than confirmed malicious activity.
## Recommended Actions
No immediate blocking recommended. The IP represents legitimate cloud hosting infrastructure with moderate risk. SOC teams should:
- Monitor for anomalous traffic patterns inconsistent with hosting operations
- Evaluate context of any observed connections against known Ahrefs service profiles
- Consider subnet-level monitoring for broader abuse trends in the 15.235.96.0/24 block
## Conclusion
15.235.96.136 is a legitimate OVH cloud hosting IP associated with Ahrefs. No actionable threat intelligence indicates malicious activity. Standard monitoring and contextual analysis advised.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059694 |
| CIDR Block | 15.235.96.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca015-san136.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca015-san136.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 20:59:20 UTC |
| Last Seen | 2026-06-28 15:26:46 UTC |
| Profile Built | 2026-06-29 09:32:42 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.