## IP Intelligence Briefing: 15.235.96.172/32
Executive Summary
IP 15.235.96.172 presents moderate risk (score: 50) with elevated neighborhood abuse density (0.7109). The address is hosted on OVH infrastructure (ASN 16276) under organization "Dmytro, Ahrefs Pte Ltd" with DNS association to ahrefs.net. While no active threat indicators are present, the IP exhibits geolocation inconsistencies and operates within a high-abuse subnet.
Infrastructure Profile
- Provider: OVH Cloud (ASN 16276)
- Organization: Dmytro, Ahrefs Pte Ltd
- CIDR Block: 15.235.96.0/24
- Infrastructure Type: CloudCompute / Hosting
- DNS PTR: proxy-ca015-san172.ahrefs.net (ahrefs.net)
- Services: No open ports detected; classified as "Firewalled / No Services"
Threat Assessment
- Risk Score: 50 (Moderate)
- Threat Indicators: None directly associated
- Blacklist Status: Listed on 2 DNS blacklists of 8 total checks
- Known Campaigns: None identified
- Network Classification: Cloud infrastructure, hosting provider environment
Neighborhood Analysis
The /24 subnet (15.235.96.0/24) demonstrates significant abuse concentration:
- Abuse Density: 0.7109 (High Abuse classification)
- Inherited Risk Score: 28
- Active Siblings: 220 of 256 total addresses
- Threat Siblings: 182 identified with threat activity
- Risk Distribution: 78 medium-risk, 22 low-risk IPs in immediate neighborhood
Geolocation Validation
- Reported Location: Singapore
- Validation Status: FAILED (geoPlausible: false)
- RTT Violation: Observed 27ms RTT vs minimum 121.6ms required for 6,082km distance
- Country Code: CA (Canada) per some sources
- Note: Geolocation data is unreliable; actual origin location cannot be confirmed
Historical Observations
Monitoring reveals consistent classification as OVH cloud infrastructure with high-abuse density designation. Recent observations (June 2026) show persistent cloud hosting classification and recurring DNS blacklist listings with high severity ratings.
Recommended Actions
Based on risk profile and neighborhood context, the following firewall rules are recommended:
```bash
# iptables
iptables -A INPUT -s 15.235.96.172 -j DROP
# nftables
nft add rule inet filter input ip saddr 15.235.96.172 drop
# Cloudflare WAF
# Block 15.235.96.172 โ IPDebrief risk score 50
# AWS WAF
# Addresses: 15.235.96.172/32
```
Intelligence Notes
- The DNS hostname "proxy-ca015-san172.ahrefs.net" suggests this may be a proxy or caching service for ahrefs.net infrastructure
- Despite moderate individual risk score, the high-abuse neighborhood (0.7109 density) warrants defensive blocking
- No active threat indicators, but the subnet's abuse profile suggests potential for future misuse
- Consider blocking the entire /24 subnet if defensive posture requires it, given 182 threat-sibling addresses
---
Briefing Generated: Intelligence compiled from comprehensive IP profile, neighborhood analysis, relationship mapping, and historical observation data.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059694 |
| CIDR Block | 15.235.96.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca015-san172.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca015-san172.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 22% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 21% | 9 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-06 13:35:08 UTC |
| Last Seen | 2026-06-29 15:18:40 UTC |
| Profile Built | 2026-06-29 15:25:49 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.