IP Intelligence Briefing: 15.235.27.181
Date: June 15, 2026
---
**1. Core Profile**
- Risk Score: 40 (Moderate Risk)
- Ownership:
- ASN: 16276 (OVH)
- Organization: Ahrefs Pte Ltd (Hosting provider)
- Subnet: 15.235.27.0/24
- Geolocation:
- Country: Canada (CA)
- City: Singapore (discrepancy noted; may indicate misconfigured geolocation)
- Accuracy Radius: 3,000 km
- Network Role:
- Cloud Compute: Hosted by OVH (likely a managed cloud instance)
- Services: No open ports or TLS services detected.
---
**2. Threat Observations**
- No Direct Threat Indicators:
- No malware, spam, or known attacker activity detected.
- DNS: Resolves to `proxy-ca013-san181.ahrefs.net` (Ahrefs-hosted domain).
- Traceroute Anomaly (June 15):
- RTT Discrepancy: Observed RTT of 28.6ms vs. expected minimum of 121.6ms for 6,082km distance.
- Geolocation Mismatch: Claimed coordinates (43.6319, -79.3716) suggest Toronto, Canada, conflicting with Singapore city label.
---
**3. Network Relationships**
- Linked Entities:
- Subnet: 15.235.27.0/24 (OVH-managed).
- DNS: Associated with Ahrefs' proxy hostname (`proxy-ca013-san181.ahrefs.net`).
- Hosting: Likely used for Ahrefs' cloud infrastructure (SEO tools).
---
**4. Subnet Analysis (15.235.27.0/24)**
- Abuse Density: 55.86% (High Abuse Classification).
- Neighbor Risk Distribution:
- Low Risk: 3 IPs
- Medium Risk: 97 IPs
- High Risk: 0 IPs
- Notable Neighbors:
- 15.235.27.0/24 (same subnet, shared risk).
- 15.235.27.181 (target IP, moderate risk).
---
**5. Recommendations**
- Monitor Subnet: Due to high abuse density, monitor traffic patterns in 15.235.27.0/24 for anomalies.
- Verify Geolocation: Investigate the Singapore vs. Canada discrepancy for potential misconfigurations or spoofing.
- Block/Restrict: Consider blocking the subnet if itβs not required for operations, as itβs associated with a high-risk network.
- Check DNS: Confirm Ahrefs' DNS configurations for potential misrouting or spoofing.
Conclusion: The IP is part of a cloud infrastructure used by Ahrefs, with no direct malicious activity. However, the subnetβs high abuse density and geolocation inconsistencies warrant closer scrutiny.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059692 |
| CIDR Block | 15.235.27.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca013-san181.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca013-san181.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 22% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-23 12:22:08 UTC |
| Last Seen | 2026-06-28 21:08:27 UTC |
| Profile Built | 2026-06-29 03:11:37 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.