IP Intelligence Briefing: 15.235.96.199
Date: June 15, 2026
---
**1. IP Profile**
- Risk Score: 25 (Low Risk)
- Provider: OVH (ASN 16276)
- Ownership: Registered to Ahrefs Pte Ltd (OVH-CUST-281059694)
- Geolocation: Canada (QC), Beauharnois (approx. 3000km accuracy radius)
- Network Role: CloudCompute (OVH infrastructure)
- Services: No open ports, no TLS certificates, no HTTP services detected.
- Threat Indicators: No malicious activity, no abuse confidence scores, not listed in DNSBLs.
---
**2. Observation History**
- Recent Activity (June 15, 2026):
- Behavioral Anomaly: RTT (Round Trip Time) of 27ms detected, which is significantly lower than the minimum possible for the claimed geolocation (121.6ms). This suggests potential IP spoofing, proxy use, or misconfigured routing.
- Network Validation: Minimal risk score (0.2174) with no threat indicators.
- Consistency: No changes in ownership or threat signals over the past 30 days.
---
**3. Relationships**
- Network Associations:
- Linked to OVH-CUST-281059694 (same subnet).
- DNS association with proxy-ca015-san199.ahrefs.net (likely internal Ahrefs infrastructure).
- No Known Threat Links: No correlations to malicious campaigns, blacklists, or known attackers.
---
**4. Neighborhood Analysis**
- Subnet: 15.235.96.0/24
- Abuse Density: 47.24% (moderate risk).
- Neighbor Risks:
- 120 of 254 IPs in the subnet show threat activity.
- 165 IPs are active, with 120 flagged as risky.
- Context: While the IP itself is low risk, the subnet has a high abuse density, suggesting potential for lateral movement or shared infrastructure risks.
---
**5. Recommendations**
- Monitor RTT Anomalies: Investigate the unusually low RTT for 15.235.96.199. This could indicate proxy use, misrouting, or spoofing.
- Subnet Risk Mitigation: Consider isolating or segmenting the 15.235.96.0/24 subnet due to its moderate abuse density.
- DNS Verification: Confirm the legitimacy of the DNS association with `proxy-ca015-san199.ahrefs.net` to ensure no unauthorized use of Ahrefs infrastructure.
- Behavioral Baseline: Establish a baseline for the IPβs traffic patterns to detect deviations (e.g., unexpected outbound connections).
---
Note: This IP appears to be part of legitimate cloud infrastructure, but the subnetβs abuse density and RTT anomaly warrant further investigation to rule out covert operations or misconfigured networks.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059694 |
| CIDR Block | 15.235.96.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca015-san199.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca015-san199.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 25% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-21 20:59:20 UTC |
| Last Seen | 2026-06-28 15:27:40 UTC |
| Profile Built | 2026-06-29 03:32:03 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.