# INTELLIGENCE BRIEFING: IP 15.204.225.154
## Classification: Moderate Risk Infrastructure
The IP address 15.204.225.154/32 was identified as belonging to OVH US LLC (ASN 16276) within the VPS-US-EAST-VA-2 cloud infrastructure network (15.204.224.0/23). The endpoint resolved geographically to Reston, Virginia, US, with DNS reverse resolution to vps-786944e6.vps.ovh.us.
Infrastructure Profile
The system operated as a cloud compute instance with standard web services exposed. Port scanning revealed TCP/80 (HTTP), TCP/443 (HTTPS), and TCP/22 (SSH-2.0-OpenSSH_10.0p2 Debian) services running on the Caddy web server stack. The IP maintained a risk score of 50, classified as Moderate Risk, with zero blacklist entries and no indicators of malicious activity (not flagged as Tor exit node, spam source, known attacker, or proxy).
Network Context
The /24 neighborhood (15.204.225.0/24) exhibited an abuse density of 0.5 with classification "mostly_clean." One active sibling IP (15.204.225.76) was observed with risk score 25 and authority score 60. The subnet contained one threat sibling within the 24-bit boundary. Control plane analysis showed the IP was not route-stable within its BGP prefix (15.204.128.0/17) and appeared on 2 out of 8 DNSBL lists.
Historical Activity
The IP generated 22 observations, with the most recent recorded on 2026-06-16. Historical signals included connection failure events, port scanning activity, and subnet-level abuse density assessments. The system maintained zero threat persistence days and zero ownership changes, indicating transient operational status rather than persistent malicious deployment.
Threat Indicators
No active threat indicators were observed. The system showed no correlation to known campaigns, zero certificate matches, and no associated correlated IPs beyond the immediate subnet relationships.
Recommended Actions
No specific mitigation actions were generated based on the risk profile. The infrastructure remains operational within its intended cloud hosting environment with no immediate threat-based blocking required.
---
*Report generated: 2026-06-16 | Intelligence Source: IPDebrief*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | OVH US LLC |
| ASN | AS16276 |
| Network Name | VPS-US-EAST-VA-2 |
| CIDR Block | 15.204.224.0/23 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | vps-786944e6.vps.ovh.us |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | vps-786944e6.vps.ovh.us |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Caddy |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_10.0p2 Debian-7+deb13u4 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 36% | 2 | 4 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 29% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-01 23:53:45 UTC |
| Last Seen | 2026-06-21 08:01:33 UTC |
| Profile Built | 2026-06-21 08:10:35 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 26 |
Full dossier details are available via our API.