Threat Intelligence Briefing: IP 15.235.96.213/32
IP Address: 15.235.96.213/32
Observation Date: [Date of Data Collection]
---
1. Ownership and Registration Data:
- Owner: The IP address 15.235.96.213 is associated with [Owner Name], registered through [Registrar Name].
- ASN: [Autonomous System Number], operated by [Network Provider].
- Location: The IP is geolocated to [Country/City], with an associated postal code of [Postal Code].
2. Historical Data and Activity:
- Activity Trends: Historical data indicates that the IP address has been active since [First Activity Date], primarily associated with [Type of Services or Websites].
- Past Incidents: There have been [Number] recorded incidents involving this IP address, predominantly categorized as [Type of Incident, e.g., phishing attempts, malware distribution].
3. Relationship and Network Neighbors:
- Subnet Analysis: The IP falls within subnet [Subnet Details], hosting [Number] other IPs, primarily used for [Service Types].
- Associated Domains: Domains frequently resolved from this IP include [Domain List], suggesting involvement in [Services or Content Type, e.g., e-commerce, media streaming].
4. Behavioral and Technical Indicators:
- Traffic Patterns: Observations reveal spikes in outbound traffic correlating with [Specific Days/Times], potentially indicative of [Activity, e.g., data exfiltration, DDoS preparation].
- Protocol Usage: Predominantly uses protocols such as [Protocol List], with unusual activity noted in [Specific Protocol], which may suggest [Potential Threat Behavior].
5. Threat Intelligence Observations:
- Threat Reports: The IP has been flagged in [Number] threat intelligence feeds for activities such as [List of Threats, e.g., command and control, botnet activity].
- Malware Associations: Linked to known malware samples [Malware Names] detected in [Number] incidents, primarily affecting [Operating Systems or Software].
6. Recommended Actions for SOC Teams:
- Monitoring: Increase monitoring of network traffic originating from or directed to this IP, with a focus on [Specific Protocols or Traffic Patterns].
- Threat Hunting: Conduct targeted threat hunting exercises based on the observed behavioral patterns and historical incident data.
- Blocking/Whitelisting: Consider blocking or whitelisting this IP based on organizational risk tolerance and the nature of the associated services.
---
Conclusion:
The IP address 15.235.96.213 has demonstrated a history of activities that could pose potential security risks. Continuous monitoring and proactive measures are advised to mitigate any threats associated with this IP. Further investigation into the associated domains and services may provide additional insights into the nature of activities conducted through this address.
---
This briefing is based on the data available up to [Date of Data Collection] and should be used in conjunction with ongoing threat intelligence updates for comprehensive threat management.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059694 |
| CIDR Block | 15.235.96.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca015-san213.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca015-san213.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 41% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 32% | 1 | 3 |
| geolocation | 40% | 2 | 3 |
| Overall | 25% | 9 | 14 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-23 12:22:09 UTC |
| Last Seen | 2026-06-28 21:12:08 UTC |
| Profile Built | 2026-06-29 03:15:00 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 23 |
Full dossier details are available via our API.