# IPDEBRIEF INTELLIGENCE BRIEFING
Target IP: 135.125.226.120/32
Date: 2026-06-26
Classification: Low Risk / Cloud Infrastructure
---
## EXECUTIVE SUMMARY
The IP address 135.125.226.120 operates as a low-risk cloud computing host within OVH GmbH's German infrastructure. Analysis reveals no active threat indicators, no malicious reputation signals, and stable operational patterns. The IP is associated with standard VPS hosting services and exhibits typical cloud infrastructure characteristics.
---
## OWNERSHIP & INFRASTRUCTURE
- Organization: OVH GmbH (ASN 16276)
- Country: Germany (DE)
- Infrastructure Type: CloudCompute / Hosting
- Network Block: 135.125.128.0/17 (BGP prefix)
- Control Plane: Route stability flagged as inconsistent, 1 route change observed in 30-day window
- DNS Classification: Valid forward DNS resolution confirmed to vps-2f1f3332.vps.ovh.net
---
## RISK ASSESSMENT
| Metric | Value | Assessment |
|---|---|---|
| Risk Score | 25 | Low |
| Provider Score | 0 | Neutral |
| Authority Score | 0 | Neutral |
| Abuse Confidence | N/A | Not applicable |
| DNSBL Listings | 1/8 | Minimal |
| Threat Indicators | None | Clean |
Key Threat Signals:
- No known attacker associations
- No Tor exit node activity
- No spam source designation
- No active malicious campaigns correlated
- No threat feed matches
---
## NETWORK CONTEXT
Subnet Analysis (135.125.226.0/24):
- Abuse Density: 0.5 (moderate baseline)
- Classification: Mostly clean
- Total Siblings: 2
- Active Siblings: 2
- Threat Siblings: 1
- Inherited Risk: 2
Neighbor IP: 135.125.226.143 (Risk Score: 40, Authority Score: 60) โ Single medium-risk neighbor detected in subnet.
---
## OBSERVATION HISTORY (24 Signals)
Recent observations (2026-06-19 to 2026-06-26) indicate:
- Geolocation: Consistent DE location with 48.86°N, 6.6°E coordinates
- Network Classification: Persistent OVH hosting classification
- Threat Persistence: 0 days
- Threat Observation Count: 1
- Is Persistently Malicious: No
- Stability: No ownership changes detected
---
## SERVICES & EXPOSURE
- Open Ports: None detected
- TLS Certificates: None
- HTTP Services: None (Firewalled / No Services)
- Connection Type: Not applicable
- Service Purpose: Firewalled / No Services
---
## SECURITY ACTIONS
Recommended Actions: None required. The IP address presents no actionable threat.
Firewall Rules: No blocking rules recommended. The IP maintains low-risk posture with no malicious indicators.
---
## INTELLIGENCE NARRATIVE
IP 135.125.226.120 operates as a legitimate OVH cloud VPS with standard hosting characteristics. The asset maintains a low-risk profile (Score: 25) with no active threat indicators or malicious reputation signals. DNS resolution confirms standard VPS infrastructure designation (vps-2f1f3332.vps.ovh.net). Network classification shows consistent cloud hosting behavior with no proxy, Tor, or VPN attributes.
The subnet environment shows moderate abuse density (0.5) with one medium-risk neighbor (135.125.226.143), though the target IP remains isolated from that risk profile. Historical observations demonstrate operational stability with no threat persistence or ownership changes.
Threat Level: LOW โ No action required. Continue standard monitoring practices.
---
*Generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH GmbH |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vps-2f1f3332.vps.ovh.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vps-45e7ec65.vps.ovh.net |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 24% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-11 15:03:59 UTC |
| Last Seen | 2026-06-27 19:30:26 UTC |
| Profile Built | 2026-06-28 19:45:08 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 29 |
Full dossier details are available via our API.