# IP INTELLIGENCE BRIEFING: 15.235.96.54/32
Classification: MODERATE RISK | Risk Score: 40
Date: Current Assessment | Status: Active Monitoring Recommended
---
## EXECUTIVE SUMMARY
IP address 15.235.96.54 is registered to OVH cloud infrastructure (ASN 16276) and associated with Ahrefs Pte Ltd. The IP exhibits moderate risk (score 40) with no active threat indicators but resides within a high-abuse-density subnet. Geolocation data shows inconsistencies requiring validation.
---
## NETWORK OWNERSHIP & CLASSIFICATION
- Provider: OVH (Cloud Compute Infrastructure)
- Organization: Dmytro, Ahrefs Pte Ltd
- Network Block: 15.235.96.0/24
- Network Role: Cloud Hosting / Firewalled (No Services Detected)
- Infrastructure Type: CloudCompute, Hosting
---
## GEOLOCATION ANALYSIS
- Claimed Location: Singapore (CA)
- Validation Status: β οΈ GEOVALIDATION VIOLATION DETECTED
- Discrepancy: Claimed distance 6082km from CA with RTT 25msβphysically impossible (minimum possible RTT: 121.6ms)
- Probe Count: 5 probes | Geo Plausible: FALSE
- Conclusion: Geolocation data unreliable; actual location unconfirmed
---
## THREAT PROFILE
- Risk Score: 40 (Moderate)
- Known Campaigns: None
- Blacklist Status: 0 listings
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Active Threat Indicators: None
---
## NEIGHBORHOOD INTELLIGENCE (15.235.96.0/24)
- Subnet Classification: HIGH ABUSE
- Abuse Density: 0.6289 (62.89%)
- Total Siblings: 256 IPs
- Active Siblings: 213
- Threat Siblings: 161 (63% of active IPs)
- Risk Distribution: 100 medium-risk neighbors, 0 high-risk
- Inherited Risk Score: 25
---
## OBSERVATION HISTORY
Recent signal observations indicate:
- Multiple blacklist listings (8 total, 1 active) with high severity
- Persistent geolocation violations
- Consistent high-abuse classification across neighborhood assessments
- Operator score: 0.2174 (Minimal)
- No persistent malicious behavior detected
---
## DNS & DOMAIN INFORMATION
- PTR Hostname: proxy-ca015-san54.ahrefs.net
- Forward Confirmed: No
- Hosted Domain: ahrefs.net
- Email Authentication: SPF/DMARC not configured
---
## SERVICE & PORT ANALYSIS
- Open Ports: None detected
- TLS Certificate: None
- HTTP Service: None
- Server Banner: None
- Status: Firewalled/No Services
---
## RECOMMENDED ACTIONS
| Platform | Action |
|---|---|
| **iptables** | `iptables -A INPUT -s 15.235.96.54 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 15.235.96.54 drop` |
| **nginx** | `deny 15.235.96.54;` |
| **Cloudflare WAF** | Block with expression: `ip.src eq 15.235.96.54` |
| **AWS WAF** | Block address 15.235.96.54/32 |
Additional Recommendation: Monitor subnet 15.235.96.0/24 for related activity given 63% threat sibling rate.
---
## ANALYST NOTES
This IP represents a moderate-risk cloud hosting address with geolocation inconsistencies. While no active threats are detected, the high-abuse neighborhood context warrants continued monitoring. The geolocation validation failure (RTT impossibility) suggests potential spoofing or routing anomalies. No immediate blocking required if traffic is legitimate Ahrefs-related, but recommend defensive blocking given the subnet-level abuse patterns.
---
*Intelligence generated by IPDebrief | For authorized defensive security purposes only*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059694 |
| CIDR Block | 15.235.96.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca015-san54.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca015-san54.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 22% | 1 | 2 |
| geolocation | 30% | 2 | 3 |
| Overall | 21% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:46 UTC |
| Last Seen | 2026-06-27 00:16:22 UTC |
| Profile Built | 2026-06-27 14:29:20 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 27 |
Full dossier details are available via our API.