# IP Intelligence Briefing: 15.235.96.68
Classification: Moderate Risk | Analysis Date: Current | Confidence: Medium
## Executive Summary
IP address 15.235.96.68 is a cloud-compute infrastructure endpoint hosted on OVH (ASN 16276) under customer identifier OVH-CUST-281059694. The IP is associated with Ahrefs network infrastructure (ahrefs.net) but presents a geolocation inconsistency and operates within a high-abuse-density subnet. No active threat indicators were observed.
## Risk Assessment
- Overall Risk Score: 50/100 (Moderate Risk)
- Subnet Abuse Classification: High Abuse (15.235.96.0/24)
- Subnet Abuse Density: 0.6406 (64.06%)
- Control Plane Risk: Listed on 2 of 8 DNS blacklists
## Infrastructure Profile
- Provider: OVH Cloud (CloudCompute infrastructure)
- Network Role: Hosting environment with firewall configuration
- DNS Resolution: proxy-ca015-san68.ahrefs.net (ahrefs.net domain)
- Services: No open ports detected; endpoint is firewalled/no services exposed
- Geolocation: Discrepancy detectedβASN records indicate Canada (CA), but geolocation data reports Singapore with 3,000km accuracy radius. RTT measurements show 27-29.8ms, inconsistent with 6,082km distance to reported location.
## Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Campaign Association: None detected
- Threat Observations: Zero persistent malicious activity
- Operator Score: 0.2174 (Minimal operator risk)
## Neighborhood Analysis (15.235.96.0/24)
- Total Siblings: 256 IPs
- Active Siblings: 205
- Threat Siblings: 164
- Risk Distribution: 0 High, 99 Medium, 1 Low
- Inherited Risk Score: 25
The subnet demonstrates elevated abuse density typical of shared cloud hosting environments. Multiple neighboring IPs show risk scores in the 40-50 range, consistent with the target IP.
## Historical Activity
Analysis of 21 historical observations indicates stable behavior with no escalation in threat activity. Recent operator scoring remains consistent at 0.2174. No campaign correlations or correlated IPs detected across the observation period.
## Recommended Actions
1. Monitor Subnet Context: Given the high-abuse classification of the /24 subnet, monitor related IPs (15.235.96.0-255) for anomalous behavior patterns.
2. Geolocation Validation: Investigate the Canada/Singapore geolocation discrepancy; may indicate misconfigured DNS or routing anomalies.
3. DNSBL Monitoring: IP is listed on 2 of 8 DNS blacklists; maintain monitoring for changes in blacklist status.
4. Allow with Scrutiny: No active threat indicators present; traffic may be permitted with logging for future correlation.
## SOC Analyst Notes
This IP represents legitimate cloud infrastructure with no active malicious indicators. The moderate risk classification stems primarily from subnet-level abuse density and geolocation inconsistencies rather than direct threat activity. Recommend monitoring rather than blocking, unless specific malicious activity is observed.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059694 |
| CIDR Block | 15.235.96.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca015-san68.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca015-san68.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 25% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-21 20:59:21 UTC |
| Last Seen | 2026-06-28 15:29:20 UTC |
| Profile Built | 2026-06-29 03:33:11 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.