IPDebrief

15.204.225.154

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# INTELLIGENCE BRIEFING: IP 15.204.225.154

## Classification: Moderate Risk Infrastructure

The IP address 15.204.225.154/32 was identified as belonging to OVH US LLC (ASN 16276) within the VPS-US-EAST-VA-2 cloud infrastructure network (15.204.224.0/23). The endpoint resolved geographically to Reston, Virginia, US, with DNS reverse resolution to vps-786944e6.vps.ovh.us.

Infrastructure Profile

The system operated as a cloud compute instance with standard web services exposed. Port scanning revealed TCP/80 (HTTP), TCP/443 (HTTPS), and TCP/22 (SSH-2.0-OpenSSH_10.0p2 Debian) services running on the Caddy web server stack. The IP maintained a risk score of 50, classified as Moderate Risk, with zero blacklist entries and no indicators of malicious activity (not flagged as Tor exit node, spam source, known attacker, or proxy).

Network Context

The /24 neighborhood (15.204.225.0/24) exhibited an abuse density of 0.5 with classification "mostly_clean." One active sibling IP (15.204.225.76) was observed with risk score 25 and authority score 60. The subnet contained one threat sibling within the 24-bit boundary. Control plane analysis showed the IP was not route-stable within its BGP prefix (15.204.128.0/17) and appeared on 2 out of 8 DNSBL lists.

Historical Activity

The IP generated 22 observations, with the most recent recorded on 2026-06-16. Historical signals included connection failure events, port scanning activity, and subnet-level abuse density assessments. The system maintained zero threat persistence days and zero ownership changes, indicating transient operational status rather than persistent malicious deployment.

Threat Indicators

No active threat indicators were observed. The system showed no correlation to known campaigns, zero certificate matches, and no associated correlated IPs beyond the immediate subnet relationships.

Recommended Actions

No specific mitigation actions were generated based on the risk profile. The infrastructure remains operational within its intended cloud hosting environment with no immediate threat-based blocking required.

---

*Report generated: 2026-06-16 | Intelligence Source: IPDebrief*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionVA
CityReston
Timezoneβ€”
Latitude38.97
Longitude-77.34

🏒 Ownership & Registration

OrganizationOVH US LLC
ASNAS16276
Network NameVPS-US-EAST-VA-2
CIDR Block15.204.224.0/23
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRvps-786944e6.vps.ovh.us
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesvps-786944e6.vps.ovh.us

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierTier 3 β€” Basic operator with some routing infrastructure
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
ServerCaddy
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_10.0p2 Debian-7+deb13u4

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
32%
23
routing
13%
11
services
36%
24
ownership
30%
23
reputation
28%
13
geolocation
35%
23
Overall29%1017
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-06-01 23:53:45 UTC
Last Seen2026-06-21 08:01:33 UTC
Profile Built2026-06-21 08:10:35 UTC
Data FreshnessLive
Signal Types24
Total Observations26
πŸ” 24 signal types Β· 26 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.