IPDebrief

15.235.96.139

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

## Intelligence Briefing: IP 15.235.96.139/32

Classification: Moderate Risk – Cloud Infrastructure Host

Date: 2026-06-14

Analysis Status: Complete

---

Executive Summary

IP address 15.235.96.139 is a cloud-hosted infrastructure endpoint associated with OVH network infrastructure. The IP exhibits a moderate risk score (40) with no direct threat indicators but operates within a high-abuse subnet environment. The endpoint shows DNS association with ahrefs.net but presents geolocation inconsistencies and lacks active open services.

---

Technical Profile

AttributeValue
**Risk Score**40 (Moderate)
**ASN**16276 (OVH)
**Organization**Dmytro, Ahrefs Pte Ltd
**Network**OVH-CUST-281059694
**CIDR Block**15.235.96.0/24
**Infrastructure Type**CloudCompute
**Hosting Status**Active
**Geolocation**CA (Singapore coordinates)
**PTR Record**proxy-ca015-san139.ahrefs.net

---

Threat Assessment

Direct Indicators:

Neighborhood Risk Profile:

The /24 subnet 15.235.96.0/24 demonstrates elevated abuse characteristics:

Service Status:

---

Historical Observations

Analysis of 22 signal observations reveals:

---

Relationship Graph

The IP maintains 49 documented relationships, predominantly network-level associations with the OVH-CUST-281059694 network block. No certificate-based or organization-level relationships beyond the hosting provider were identified.

---

Recommended Actions

Immediate Mitigation:

```bash

# iptables

iptables -A INPUT -s 15.235.96.139 -j DROP

# nftables

nft add rule inet filter input ip saddr 15.235.96.139 drop

# nginx

deny 15.235.96.139;

# pfSense

15.235.96.139/32

# Cloudflare WAF

{"description":"Block 15.235.96.139 β€” IPDebrief risk score 40","action":"block","filter":{"expression":"ip.src eq 15.235.96.139"}}

# AWS WAF

{"Addresses":["15.235.96.139/32"],"Description":"IPDebrief risk 40"}

```

Additional Considerations:

1. Subnet-level Analysis: Consider evaluating the entire 15.235.96.0/24 subnet given the high abuse density (0.5882).

2. DNSBL Verification: The IP shows 1 DNS blacklist listingβ€”verify relevance to your threat context.

3. Geolocation Discrepancy: Investigate the CA/Singapore geolocation inconsistency; may indicate routing anomalies or data source conflicts.

4. a hrefs.net Association: Legitimate domain ownership requires verification against known ahrefs infrastructure patterns.

---

Intelligence Confidence

Data Quality: Moderate

Action Priority: Medium

---

*Report generated by IPDebrief Intelligence Platform*

*Analysis based on real-time network intelligence data*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡¨πŸ‡¦ Canada
Regionβ€”
CitySingapore
Timezoneβ€”
Latitude43.63
Longitude-79.37

🏒 Ownership & Registration

OrganizationDmytro, Ahrefs Pte Ltd
ASNAS16276
Network NameOVH-CUST-281059694
CIDR Block15.235.96.0/24
RIRARIN
CountrySingapore
Abuse Contactβ€”

🌐 DNS Intelligence

PTRproxy-ca015-san139.ahrefs.net
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-ca015-san139.ahrefs.net

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
32%
24
routing
13%
11
services
15%
22
ownership
15%
22
reputation
28%
13
geolocation
23%
22
Overall21%1014
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-10 10:13:15 UTC
Last Seen2026-06-27 17:22:31 UTC
Profile Built2026-06-28 11:27:49 UTC
Data FreshnessLive
Signal Types21
Total Observations26
πŸ” 21 signal types Β· 26 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.