## IP INTELLIGENCE BRIEFING
Target IP: 15.204.243.157/32
Classification: Cloud Infrastructure / Hosting Provider
Risk Level: LOW (Risk Score: 25)
---
EXECUTIVE SUMMARY
IP 15.204.243.157 is a low-risk cloud hosting address operated by OVH US LLC from Reston, VA. The IP resolves to an OVH VPS hostname and shows minimal threat indicators. Current observations indicate the IP is not actively malicious, though it carries a single blacklist listing.
---
OWNERSHIP & INFRASTRUCTURE
- Organization: OVH US LLC (ASN: 16276)
- Network Block: 15.204.128.0/17
- Infrastructure Type: Cloud Compute / Hosting
- Geolocation: Reston, VA, United States
- DNS Resolution: vps-ed714d4b.vps.ovh.us (forward confirmed)
---
THREAT ASSESSMENT
- Risk Score: 25 / 100 (Low Risk)
- Abuse Confidence: Not elevated
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 1 (minimal)
- Threat Persistence: 0 days
- Persistent Malicious: No
---
NETWORK BEHAVIOR
- Services: No open ports detected (firewalled/no services)
- TLS/Certificates: None observed
- Network Classification: Cloud provider infrastructure (not CDN, VPN, or proxy)
- Control Plane: Origin ASN 16276, BGP prefix 15.204.128.0/17
- DNSBL Listed: 1 of 8 total lists
---
TEMPORAL ANALYSIS
Observation History: 18 signals tracked
- Most Recent Signal: 2026-06-20T22:07:12 UTC
- Subnet Abuse Density: 1 (mostly_clean)
- Inherited Risk: 2 / 100
- Threat Siblings in /24: 1
- Ownership Changes: 0
- Threat Observation Count: 1
The IP shows stable ownership with no persistent malicious behavior. Single threat observation recorded but not persistent.
---
RELATIONSHIP GRAPH
Total Relationships: 33
- Network Associations: VPS-US-EAST-VA-2 (OVH infrastructure)
- DNS Associations: vps-ed714d4b.vps.ovh.us
- Classification: Standard cloud VPS within OVH US-East datacenter
---
NEIGHBORHOOD ANALYSIS
Subnet: 15.204.243.157/24
- Abuse Density: 0 (low)
- Neighbor Count: 0
- Risk Distribution: No high/medium risk neighbors identified
- Classification: Mostly clean subnet with minimal threat activity
---
SOC RECOMMENDATIONS
Action: Monitor / Standard Allow
Justification: The IP exhibits typical cloud provider behavior with no active threat indicators. Single blacklist listing warrants routine monitoring but does not indicate active compromise. No firewall blocking recommended.
Recommended Actions:
- Standard logging for forensic purposes
- No immediate blocking required
- Include in baseline monitoring for OVH cloud infrastructure
- Review blacklist listing source if security policy requires
---
INTELLIGENCE CONCLUSION
This IP represents legitimate cloud hosting infrastructure with minimal risk exposure. The single blacklist listing is likely historical or related to shared infrastructure. No active threat campaign indicators, no service enumeration, and stable network behavior observed across the 18-signal history. Treat as low-risk cloud endpoint.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | OVH US LLC |
| ASN | AS16276 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | vps-ed714d4b.vps.ovh.us |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | vps-ed714d4b.vps.ovh.us |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 21% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-24 12:33:44 UTC |
| Last Seen | 2026-06-29 00:00:48 UTC |
| Profile Built | 2026-06-29 06:03:21 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.