# IP Intelligence Briefing: 15.235.96.22
## Executive Summary
IP address 15.235.96.22 is a moderate-risk (score 40) cloud compute resource hosted by OVH under organization Dmytro, Ahrefs Pte Ltd. While the specific IP shows no direct threat indicators, it resides within a subnet exhibiting high abuse density (0.6719). The IP is currently firewalled with no active services. Geographic validation data is inconsistent, indicating potential spoofing or misconfiguration.
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 40 (Moderate) |
| **ASN** | 16276 (OVH) |
| **Organization** | Dmytro, Ahrefs Pte Ltd |
| **Network** | 15.235.96.0/24 |
| **Infrastructure** | CloudCompute (OVH) |
| **PTR Hostname** | proxy-ca015-san22.ahrefs.net |
| **Forward Resolution** | proxy-ca015-san22.ahrefs.net |
| **DNSSEC** | Valid |
| **Services** | None detected (firewalled) |
## Geographic Analysis
- Reported Location: Canada (CA), City: Singapore
- Validation Status: Inconsistent
- Distance: 6,082 km
- Observed RTT: 25-31ms
- Minimum Possible RTT: 121.6ms
- GeoPlausible: False
- Probe Count: 5
- Analysis: Significant RTT violation indicates geographic data may be spoofed or the IP is misconfigured. The RTT is approximately half the minimum physically possible value for the reported distance.
## Neighborhood Assessment
The /24 subnet (15.235.96.0/24) shows elevated abuse activity:
- Abuse Density: 0.6719 (high)
- Subnet Classification: high_abuse
- Total Siblings: 256
- Active Siblings: 213 (83%)
- Threat Siblings: 172 (68% of active)
- Inherited Risk: 26
- Risk Distribution: 0 high, 98 medium, 2 low
This indicates the subnet hosts multiple potentially compromised or misconfigured resources. The high abuse density is inherited risk rather than direct threat indicators on this specific IP.
## Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 lists
- Campaign Matches: None
- Threat Feeds: None populated
## Temporal Analysis
- Total Observations: 24 signals
- Observation Period: June 17-18, 2026
- Ownership Changes: 0
- Threat Persistence: 0 days
- Risk Trend: Consistent moderate risk profile with no significant changes over observation period
## Control Plane Status
- Origin ASN: 16276
- BGP Prefix: 15.235.0.0/17
- Route Stability: False
- RPKI State: Unknown
- Operator Score: 0.2174 (Minimal)
- DNSSEC: Valid
- CAA Records: Present
## Security Recommendations
Based on risk profile and subnet abuse context, the following firewall rules are recommended:
```bash
# iptables
iptables -A INPUT -s 15.235.96.22 -j DROP
# nftables
nft add rule inet filter input ip saddr 15.235.96.22 drop
```
Additional Actions:
- Block at application layer (nginx, pfSense, Cloudflare WAF, AWS WAF)
- Monitor for emerging threat indicators
- Consider blocking entire /24 subnet if abuse patterns warrant
## Risk Assessment
This IP presents moderate risk primarily due to:
1. High-abuse-density subnet association (172 threat siblings in /24)
2. Geolocation inconsistencies suggesting potential spoofing
3. Cloud hosting environment commonly exploited for malicious activity
4. No services exposed reduces immediate exploitation risk
The IP should be blocked or monitored based on organizational security policy regarding cloud provider risk tolerance. No direct evidence of malicious activity on this specific IP, but subnet context warrants defensive measures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059694 |
| CIDR Block | 15.235.96.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca015-san22.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca015-san22.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:46 UTC |
| Last Seen | 2026-06-27 00:12:52 UTC |
| Profile Built | 2026-06-27 14:25:53 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 29 |
Full dossier details are available via our API.