# INTELLIGENCE BRIEFING: 15.235.96.31/32
Classification: MODERATE RISK โ DEFENSIVE RECOMMENDATION REQUIRED
## Executive Summary
IP 15.235.96.31 operates within OVH infrastructure under customer block OVH-CUST-281059694 (ASN 16276). The asset presents moderate risk (score: 40) with no active threat indicators. However, the /24 subnet exhibits elevated abuse density (0.5352), with 137 of 256 sibling IPs flagged as threats. The IP resolves to ahostnames associated with ahrefs.net but shows no open services.
## Ownership and Infrastructure
- Organization: OVH-CUST-281059694 (Ahrefs Pte Ltd)
- ASN: 16276 (OVH)
- Network Block: 15.235.96.0/24
- Infrastructure Type: CloudCompute (hosting enabled)
- Control Plane: BGP prefix 15.235.0.0/17, route stability compromised
## Geolocation and Validation
Reported location: Singapore (CA). Validation anomaly detected: RTT measurements (26-28.6ms) are inconsistent with 6,082km distance from probe origin (minimum expected: 121.6ms). Geolocation flagged as implausible. Multiple geolocation sources required manual validation.
## Network Behavior
- Services: None detected (firewalled/no services)
- DNS PTR: proxy-ca015-san31.ahrefs.net
- Forward Resolution: Confirmed to ahrefs.net domain
- TLS/HTTP: No active web services
- Email Auth: SPF/DMARC not configured
## Threat Indicators
- Risk Score: 40/100 (Moderate)
- Threat Feeds: No active indicators
- Blacklist Status: 0 lists
- Known Campaigns: None
- Tor Exit Node: No
- Residential/Proxy: No
## Subnet Risk Profile
The 15.235.96.0/24 subnet presents elevated risk:
- Abuse Density: 0.5352 (high abuse classification)
- Active Siblings: 221 of 256 IPs
- Threat Siblings: 137 flagged as threats
- Inherited Risk: 21/100
## Observation History
22 signal observations recorded over recent timeframe. Primary signals include DNS resolution events and network classification data. No persistent malicious activity detected; threat observation count: 1.
## Recommended Actions
Despite moderate individual risk, the high-abuse subnet environment warrants defensive blocking:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 15.235.96.31 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 15.235.96.31 drop` |
| nginx | `deny 15.235.96.31;` |
| Cloudflare WAF | Block with expression: `ip.src eq 15.235.96.31` |
| AWS WAF | Add 15.235.96.31/32 to rule set |
Note: Consider blocking the entire /24 subnet (15.235.96.0/24) given 137 threat siblings and high abuse density.
## Intelligence Assessment
This IP is a legitimate cloud-hosted asset with no active threat indicators. However, the subnet's elevated abuse profile and geolocation validation anomalies suggest potential for misconfiguration or compromised infrastructure. Recommend blocking at perimeter firewall level while monitoring for lateral activity from related subnet addresses.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059694 |
| CIDR Block | 15.235.96.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca015-san31.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca015-san31.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 37% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-09 17:41:10 UTC |
| Last Seen | 2026-06-27 16:00:51 UTC |
| Profile Built | 2026-06-28 10:06:59 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 27 |
Full dossier details are available via our API.