# INTELLIGENCE BRIEFING: 135.125.103.129
## EXECUTIVE SUMMARY
IP address 135.125.103.129/32 is classified as a Low Risk infrastructure endpoint. The IP is hosted on OVH SAS cloud infrastructure and shows no active threat indicators. No recommended defensive actions are required at this time.
## OWNERSHIP & INFRASTRUCTURE
| Attribute | Value |
|---|---|
| **Organization** | OVH SAS |
| **ASN** | 16276 |
| **Network Block** | 135.125.100.0/22 (VPS-SBG6) |
| **Infrastructure Type** | Cloud Compute / Hosting |
| **Geolocation** | France (FR) - Europe/Paris timezone |
## NETWORK SERVICES & PORTS
The IP maintains standard web hosting services:
- Port 80/TCP - HTTP
- Port 443/TCP - HTTPS
- Port 22/TCP - SSH (OpenSSH_8.9p1 Ubuntu-3ubuntu0.16)
- Port 8443/TCP - HTTPS-alt
Server Fingerprint: nginx
TLS Certificate: CN=cloudpanel.clp (valid certificate, self-signed: false)
## THREAT ASSESSMENT
- Risk Score: 30/100 (Low Risk)
- Abuse Confidence Score: Not applicable
- Known Attacker Status: Negative
- Tor Exit Node: False
- Spam Source: Negative
- Blacklist Status: 0 confirmed listings (null abuseConfidenceScore)
- DNSBL Listed: 1 of 8 total lists
- Known Campaigns: None detected
## HISTORICAL OBSERVATIONS
Analysis of 24 historical signal observations indicates:
- Geolocation signals consistently report France with ~500km accuracy radius
- No persistent malicious activity detected
- Threat persistence days: 0
- Ownership stability: No changes recorded
- Recent observations (2026-08-12) show consistent low-risk characteristics
## NETWORK RELATIONSHIPS
- Primary Network Association: VPS-SBG6 (OVH SAS)
- Subnet Classification: Clean
- Related Entities: 10 relationship entries (primarily network associations)
- Control Plane: Route stable, DNSSEC valid
## NEIGHBORHOOD ANALYSIS
Subnet: 135.125.103.129/24
- Abuse Density: 0 (clean)
- Neighbor Count: 0 detected
- Threat Siblings: 0
- Classification: Clean subnet with no inherited risk
## RECOMMENDATIONS
No immediate defensive actions recommended. The IP presents as legitimate cloud hosting infrastructure with standard web services. However, SOC teams should maintain awareness of the following:
1. DNSBL Listing: Single DNSBL listing detected (verify source and context)
2. SSH Access: Port 22 is open - ensure legitimate traffic patterns
3. Cloud Hosting: Standard OVH infrastructure; monitor for behavioral anomalies
## CONCLUSION
This IP address represents a standard low-risk cloud hosting endpoint with no evidence of malicious activity. The infrastructure profile is consistent with legitimate web hosting services. No blocking or mitigation actions are warranted at this time.
---
*Intelligence generated by IPDebrief analytical suite*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH SAS |
| ASN | AS16276 |
| Network Name | VPS-SBG6 |
| CIDR Block | 135.125.100.0/22 |
| RIR | ARIN |
| Country | FR |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| 8443 | https-alt | tcp | โ |
| Closed Ports | 25, 3389, 8080 (4 open / 7 scanned) | ||
| Server | nginx |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16 |
๐ TLS Certificate
CN=cloudpanel.clp was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.| SANs | cloudpanel.clpwww.cloudpanel.clp |
| Valid From | 2019-10-14T13:34:38+00:00 |
| Valid Until | 2020-10-13T13:34:38+00:00 (expired) |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 365 days |
| Serial Number | 00 |
| Thumbprint | 3BECE07FF14C8422E15E2D725E47F72289009311 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 32% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 30% | 2 | 3 |
| Overall | 25% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-28 10:06:09 UTC |
| Last Seen | 2026-08-12 22:21:00 UTC |
| Profile Built | 2026-08-12 22:27:04 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.