# IP Intelligence Briefing: 15.235.96.35/32
Date: 2026-06-17
Classification: Moderate Risk / High-Abuse Neighborhood
Source: IPDebrief Threat Intelligence Platform
---
## Executive Summary
IP 15.235.96.35 is a cloud hosting endpoint operated by OVH (ASN 16276) under the organization Dmytro, Ahrefs Pte Ltd. The IP presents a moderate risk profile (score: 40) but operates within a high-abuse density subnet (abuse density: 0.6719). The endpoint is associated with the ahrefs.net domain infrastructure and is currently firewalled with no active services.
---
## Network & Ownership Profile
| Attribute | Value |
|---|---|
| **ASN** | 16276 |
| **Organization** | Dmytro, Ahrefs Pte Ltd |
| **Network Block** | 15.235.96.0/24 |
| **Provider** | OVH (CloudCompute) |
| **Infrastructure Type** | Cloud Hosting |
| **IP Classification** | Cloud Endpoint |
| **Risk Score** | 40 (Moderate) |
| **Status** | Active, Firewalled |
---
## Threat Indicators
- Threat Classification: Moderate Risk
- Known Campaigns: None identified
- Known Attacker Status: False
- Spam Source: False
- Tor Exit Node: False
- Blacklist Count: 0
- DNSBL Listings: 1 of 8 lists
- Operator Score: 0.2174 (Minimal)
---
## Neighborhood Analysis (15.235.96.0/24)
| Metric | Value |
|---|---|
| **Total Subnet IPs** | 256 |
| **Active Siblings** | 213 |
| **Threat Siblings** | 172 |
| **Abuse Density** | 0.6719 (High) |
| **Risk Distribution** | 0 High, 98 Medium, 2 Low |
The subnet exhibits significant abuse activity with 67% abuse density. The target IP is surrounded by 172 known threat-sibling endpoints, indicating this is a shared cloud infrastructure block with elevated malicious activity.
---
## DNS & Infrastructure
| Attribute | Value |
|---|---|
| **PTR Hostname** | proxy-ca015-san35.ahrefs.net |
| **Domain** | ahrefs.net |
| **Forward Resolution** | Confirmed (1 hostname) |
| **Open Ports** | None (Firewalled) |
| **TLS Certificate** | None |
| **HTTP Service** | None |
| **SPF Record** | Not configured |
| **DMARC Record** | Not configured |
---
## Geolocation
| Attribute | Value |
|---|---|
| **Country** | Singapore (CA with 3000km radius) |
| **City** | Singapore |
| **Accuracy Radius** | 3000km |
| **Geo Plausibility** | True |
| **Minimum Possible RTT** | 121.6ms |
| **Observed RTT** | ~485-545ms |
*Note: Geographic discrepancy detected between reported CA and plausible Singapore location. 3000km accuracy radius indicates geolocation uncertainty.*
---
## Temporal Analysis & History
- Observation Count: 21 signals over observation period
- Recent Classification: Consistent "high_abuse" subnet classification
- Threat Persistence: 0 days
- Ownership Changes: 0
- Recent Signals (June 13-17, 2026):
- Subnet abuse density maintained at 0.6719
- Operator score stable at 0.2174
- Geographic signals show CA reporting with 35% confidence
---
## Relationship Graph
- Total Relationships: 43
- Primary Association: OVH-CUST-281059694 (Network)
- Network Consistency: Multiple "Same Network" relationships to OVH customer subnet
- No Certificate or Hostname Correlations Identified
---
## Security Recommendations
1. Allow/Block Decision: Given moderate risk score (40) and association with legitimate ahrefs.net infrastructure, default action should be ALLOW unless specific malicious activity is observed.
2. Neighborhood Context: Monitor traffic patterns due to high-abuse density (0.6719) in parent subnet. 172 threat siblings indicate elevated risk environment.
3. Traffic Analysis: Apply behavioral analysis for outbound connections from this subnet. Cloud hosting environments in this block show mixed legitimate and malicious use.
4. DNS Policy: Monitor for DNS queries to proxy-ca015-san35.ahrefs.net for potential credential harvesting or proxy abuse.
5. GeoValidation: Investigate geographic reporting discrepancies between CA and Singapore data for potential spoofing or data center misreporting.
---
Analyst Notes: This endpoint represents legitimate cloud infrastructure with moderate risk. However, the high-abuse neighborhood context warrants ongoing monitoring. No immediate blocking recommended without additional threat intelligence correlation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059694 |
| CIDR Block | 15.235.96.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca015-san35.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca015-san35.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:46 UTC |
| Last Seen | 2026-06-27 00:15:52 UTC |
| Profile Built | 2026-06-27 14:29:20 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 28 |
Full dossier details are available via our API.