IPDebrief

15.235.197.254

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

## INTELLIGENCE BRIEFING: 15.235.197.254/32

Classification: Moderate Risk Cloud Infrastructure

Analysis Date: 2026-06-26

Risk Score: 40/100

---

EXECUTIVE SUMMARY

IP address 15.235.197.254 is associated with OVH Singapore PTE. LTD (ASN 16276) and operates as cloud infrastructure in Canada. The IP presents moderate risk with no active threat indicators, limited neighborhood contamination, and a history of persistent cloud hosting patterns. Recommended defensive action: Block at perimeter unless traffic requires investigation.

---

INFRASTRUCTURE PROFILE

AttributeValue
**Organization**OVH Singapore PTE. LTD
**ASN**16276
**Network**VPS-SGP2 (SGP2)
**Country**Canada (CA)
**Infrastructure Type**CloudCompute
**Hosting Provider**OVH
**IPv6 Support**No (IPv4 only)
**DNS Resolution**vps-d3632732.vps.ovh.ca

Network Classification: Cloud hosting environment with no active services (firewalled/no services detected). No open ports, no TLS certificates, no HTTP services observed.

---

THREAT ASSESSMENT

Current Risk Level: Moderate (Score 40)

Threat Indicators:

Abuse Confidence: No confidence score available (insufficient data)

DNSBL Listing: 2 out of 8 total lists

Operator Score: 0.2609 (Basic)

Behavioral Characteristics:

---

NEIGHBORHOOD ANALYSIS (15.235.197.254/24)

Subnet Assessment: mostly_clean

Risk Distribution: High: 0, Medium: 0, Low: 0

The /24 subnet demonstrates minimal contamination with only one threat-adjacent IP in active use.

---

RELATIONSHIP GRAPH

DNS Associations:

Network Relationships:

Total Related Entities: 55 associations identified

---

OBSERVATION HISTORY

Total Historical Observations: 22

Recent Signals (2026-06-26):

Temporal Patterns:

---

DEFENSIVE RECOMMENDATIONS

Recommended Action: BLOCK (Perimeter/IDS)

Risk Score: 40

Firewall Rules:

Risk-Based Decision Matrix:

Risk ToleranceRecommended Action
LowBlock immediately
MediumBlock; monitor for legitimate traffic
HighAllow with logging; investigate if suspicious activity detected

---

INTELLIGENCE NOTES

1. Provider Context: OVH is a legitimate cloud hosting provider with minimal abuse density in this subnet.

2. Infrastructure Type: Cloud compute environment with strict firewalling (no services exposed).

3. Geographic Mismatch: Registered organization indicates Singapore; geolocation data indicates Canada. This discrepancy warrants monitoring but is not inherently suspicious for cloud hosting.

4. DNS Consistency: Stable PTR records with OVH infrastructure naming conventions.

5. Actionability: Moderate risk score (40) suggests blocking is appropriate for most defensive postures.

---

Analyst Assessment: This IP represents a cloud hosting endpoint with moderate risk scoring. No active threat indicators detected. The IP should be blocked at perimeter unless legitimate traffic requirements exist. The subnet shows minimal contamination, suggesting the IP operates as a legitimate cloud resource rather than compromised infrastructure.

Classification: UNCLASSIFIED

Distribution: SOC Team, Security Operations

Retention: 365 days

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡จ๐Ÿ‡ฆ Canada
Regionโ€”
Cityโ€”
Timezoneโ€”
Latitude1.37
Longitude103.80

๐Ÿข Ownership & Registration

OrganizationOVH Singapore PTE. LTD
ASNAS16276
Network Nameโ€”
CIDR Blockโ€”
RIRARIN
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRvps-d3632732.vps.ovh.ca
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesvps-48c61801.vps.ovh.ca

๐Ÿ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
26%
24
routing
13%
11
services
24%
23
ownership
20%
23
reputation
28%
13
geolocation
23%
22
Overall22%1016
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-10 10:13:14 UTC
Last Seen2026-06-27 17:22:43 UTC
Profile Built2026-06-28 11:27:49 UTC
Data FreshnessLive
Signal Types22
Total Observations28
๐Ÿ” 22 signal types ยท 28 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.