IP Intelligence Briefing: 15.235.96.149
*Generated via IPDebrief Threat Intelligence Platform*
---
**1. Core Profile**
- Risk Score: 40 (Moderate Risk)
- Ownership:
- ASN: AS16276 (OVH)
- Organization: Ahrefs Pte Ltd (OVH-CUST-281059694)
- Geolocation: Singapore (CA country code), inferred via DNS records.
- Threat Indicators:
- No malicious indicators, blacklists, or campaigns detected.
- BGP analysis shows stable route with no recent changes.
- Network Role:
- CloudCompute infrastructure (OVH-hosted).
- No evidence of CDN, VPN, proxy, or Tor usage.
---
**2. Observation History (Last 15 Days)**
- Key Signals:
- Detected in high-abuse subnet (15.235.96.0/24) with 52.55% abuse density.
- Scans and network activity observed (June 10โ15, 2026), but no confirmed threats.
- DNS resolution linked to `proxy-ca015-san149.ahrefs.net` (Ahrefs subdomain).
- Trends:
- No persistent malicious behavior; risk score stable.
---
**3. Relationships & Context**
- Network Connections:
- Same subnet (`15.235.96.0/24`) with 167 active IPs, 134 flagged as threats.
- Direct DNS association with `proxy-ca015-san149.ahrefs.net` (Ahrefs subdomain).
- Organizational Links:
- Owned by OVH, associated with Ahrefs (web hosting provider).
- No ties to known malicious organizations or campaigns.
---
**4. Subnet Analysis**
- Subnet Risk:
- Abuse Density: 52.55% (high risk).
- Neighbor Risk: 96 IPs classified as medium/low risk, 4 high-risk siblings.
- Inherited Risk: 21% (due to subnet-level threats).
- Actionable Insight:
- Monitor subnet for lateral movement or compromised hosts.
- Isolate high-risk neighbors (e.g., IPs with >50 risk score).
---
**5. Recommendations**
- Network Segmentation:
- Segment the `15.235.96.0/24` subnet to limit lateral movement.
- DNS Monitoring:
- Track DNS queries to `proxy-ca015-san149.ahrefs.net` for anomalies.
- Threat Hunting:
- Investigate high-risk siblings (e.g., IPs with >50 risk score) for potential compromise.
- Firewall Rules:
- Block high-risk neighbors using IPDebrief-generated rules (e.g., iptables, Cloudflare WAF).
---
Note: This IP appears legitimate (OVH-hosted Ahrefs service), but its subnet exhibits elevated risk. Prioritize monitoring and segmentation to mitigate potential exposure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059694 |
| CIDR Block | 15.235.96.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca015-san149.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca015-san149.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 22% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 22% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-23 18:28:44 UTC |
| Last Seen | 2026-06-28 22:29:28 UTC |
| Profile Built | 2026-06-29 16:34:02 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.