## IP INTELLIGENCE BRIEFING: 15.204.226.23/32
EXECUTIVE SUMMARY
IP address 15.204.226.23 is classified as LOW RISK with a risk score of 25. The IP operates as a cloud-hosted VPS through OVH US LLC (ASN 16276) with no active threat indicators detected. No malicious campaigns, blacklist entries, or known attacker associations were identified.
INFRASTRUCTURE PROFILE
- Provider: OVH US LLC (ASN 16276)
- Infrastructure Type: Cloud hosting / VPS
- Network Block: 15.204.128.0/17
- Service Status: Firewalled / No services exposed
- DNS Resolution: vps-71647c0d.vps.ovh.us
- PTR Record: healmake15.204.226.23.healthtechmke.com
- Email Authentication: SPF and DMARC records present
GEOLOCATION ANALYSIS
- Reported Location: Reston, VA, US
- Geolocation Confidence: Low (implausible data)
- Critical Finding: RTT validation failureβmeasured 26ms latency is significantly below the 126.2ms minimum possible for the reported 6,309km distance. This indicates geolocation data may be inaccurate or spoofed.
THREAT INDICATORS
- Blacklist Count: 0
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Abuse Confidence: Not applicable
- Known Campaigns: None identified
- DNSBL Listed: 1 of 8 lists (minor listing)
NETWORK NEIGHBORHOOD (15.204.226.0/24)
- Abuse Density: Low (1)
- Classification: Mostly clean
- Active Siblings: 1
- Threat Siblings: 1
- High Risk Neighbors: 0
OBSERVATION HISTORY
22 signal observations recorded (most recent: 2026-06-26). Key patterns:
- Consistent cloud/hosting classification
- Operator score: 0.2609 (Basic)
- No persistent malicious activity detected
- Historical threat observation count: 1 (transient)
RELATIONSHIPS
- DNS Associations: Multiple records for healmake15.204.226.23.healthtechmke.com
- Network Association: VPS-US-EAST-VA-2
- Control Plane: Route stability flagged as inconsistent
SECURITY ACTIONS & RECOMMENDATIONS
Based on the low-risk profile and absence of active threats:
- Firewall: No blocking required; IP may be monitored for future activity
- Monitoring: Standard logging recommended due to geolocation validation concerns
- Threat Response: No immediate defensive actions warranted
CONCLUSION
IP 15.204.226.23 represents a low-risk, cloud-hosted infrastructure asset with no current malicious indicators. While geolocation data validation failure warrants periodic review, the IP does not require immediate threat mitigation actions. SOC teams may track but should not prioritize this address for blocking or aggressive mitigation measures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | OVH US LLC |
| ASN | AS16276 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | healmake15.204.226.23.healthtechmke.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | vps-71647c0d.vps.ovh.us |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.9 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 22% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 28% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 24% | 1 | 3 |
| geolocation | 37% | 2 | 3 |
| Overall | 24% | 10 | 17 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-11 02:50:21 UTC |
| Last Seen | 2026-06-27 18:47:11 UTC |
| Profile Built | 2026-06-28 12:53:09 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 28 |
Full dossier details are available via our API.