INTELLIGENCE BRIEFING: IP 15.235.96.8/32
Classification: Moderate Risk / Cloud Infrastructure
Date: Intelligence generated from IPDebrief analysis
Risk Score: 40/100
---
EXECUTIVE SUMMARY
IP address 15.235.96.8 is a cloud infrastructure endpoint associated with Ahrefs Pte Ltd, hosted on OVH network. The IP presents moderate risk characteristics with no active threat indicators, though neighborhood context indicates elevated abuse density within the hosting subnet. SOC teams should monitor but may not require immediate blocking unless additional correlation signals emerge.
---
OWNERSHIP & INFRASTRUCTURE
- Organization: Dmytro, Ahrefs Pte Ltd
- Network Name: OVH-CUST-281059694
- ASN: 16276 (OVH)
- CIDR Block: 15.235.96.0/24
- Infrastructure Type: CloudCompute
- Service Status: Firewalled / No Services
- Registration: ARIN (registration date unavailable)
Geolocation Anomaly: Geographic data shows Singapore coordinates but country code CA (Canada). Distance calculation indicates 6,082 km from probe location with minimum possible RTT of 121.6ms, but observed RTT was 27msβsignificant discrepancy requiring verification.
---
THREAT INDICATORS
- Threat Classification: No known attacker, spam source, or Tor exit node
- Blacklist Status: 1 DNSBL listing out of 8 total lists
- Campaign Association: None identified
- Known Campaigns: 0 matches
- Abuse Confidence Score: Not available
Positive Signals:
- Domain resolves to ahrefs.net (legitimate SEO tools provider)
- Has CAA records configured
- DNSSEC valid
---
NEIGHBORHOOD ANALYSIS
- Subnet: 15.235.96.0/24
- Abuse Density: 0.6484 (High Abuse Classification)
- Total Siblings: 256
- Active Siblings: 208
- Threat Siblings: 166
- Inherited Risk: 25
Neighboring IPs show predominantly medium risk scores (99/100 medium, 1/100 low). The subnet exhibits elevated abuse activity, though the subject IP has no direct threat indicators.
---
OBSERVATION HISTORY
- Total Observations: 19 signals
- Recent Activity: DNS resolution to ahrefs.net observed (2026-06-20)
- Threat Persistence: 0 days (not persistently malicious)
- Ownership Changes: 0
- Signal Evolution: Neighborhood classification consistently reported as high_abuse
---
NETWORK RELATIONSHIPS
- Total Relationships: 32
- Primary Association: Same Network (OVH-CUST-281059694)
- Network Type: Cloud hosting infrastructure
---
RECOMMENDED ACTIONS
Firewall Blocking Rules:
```bash
# iptables
iptables -A INPUT -s 15.235.96.8 -j DROP
# nftables
nft add rule inet filter input ip saddr 15.235.96.8 drop
# nginx
deny 15.235.96.8;
```
WAF Integration:
- Cloudflare: Block IP with expression `ip.src eq 15.235.96.8`
- AWS WAF: Add 15.235.96.8/32 to block list
Assessment: No specific recommendations generated. The moderate risk score (40) combined with legitimate business domain (ahrefs.net) suggests defensive blocking is optional. Monitor for behavioral changes.
---
SOC ANALYST NOTES
- IP lacks direct threat indicators but operates in high-abuse-density subnet
- Geolocation data inconsistent (CA country code, Singapore coordinates)
- No open ports or active services detected
- DNS resolution confirms legitimate Ahrefs infrastructure
- Consider blocking if organization policy requires subnet-level protection
- Monitor for any emergence of threat indicators in observation history
Status: Monitor (No immediate action required unless additional signals correlate)
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059694 |
| CIDR Block | 15.235.96.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca015-san8.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca015-san8.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 32% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 9 | 13 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-23 12:22:10 UTC |
| Last Seen | 2026-06-28 21:13:28 UTC |
| Profile Built | 2026-06-29 03:17:13 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.