## INTELLIGENCE BRIEFING: 15.235.224.155/32
Date: Analysis completed based on current available data
Classification: Moderate Risk (Score: 50/100)
Status: Cloud-hosted infrastructure under OVH Singapore PTE LTD
---
OWNERSHIP & GEOLOCATION
- Organization: OVH Singapore PTE LTD (ASN 16276)
- Network: SD-ONENETWORK (15.235.224.0/24)
- Geolocation: Canada (CA)
- Infrastructure Type: Cloud Compute (hosting provider)
- Registration: ARIN registry
NETWORK SERVICES
- Open Ports: 80/TCP (HTTP), 443/TCP (HTTPS), 22/TCP (SSH)
- Server Stack: Apache/2.4.62 (AlmaLinux), OpenSSL/3.2.2
- HTTP Version: 2.0
- TLS: TLS 1.3 with strong cipher suite (TLS_AES_256_GCM_SHA384)
- TLS Certificate: Issued by Amazon RSA 2048 M01 for domain be.play-studios.ai
DNS & EMAIL AUTH
- PTR Record: ns5031674.ip-15-235-224.net
- DNSSEC: Valid
- SPF: Configured
- DMARC: Not configured
- DNSBL Status: Listed on 2 of 8 checked DNSBLs
THREAT INDICATORS
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit: No
- Abuse Confidence Score: Not available
- Campaign Correlation: None identified
OBSERVATION HISTORY
18 observations recorded as of August 13, 2026. Recent scans indicate:
- HTTP response status: 403 (Forbidden)
- TTFB: 824ms average
- RTT: 265.2ms average (10,372.4km from geolocation claim)
- Server fingerprint consistent across observations
NEIGHBORHOOD ANALYSIS
- Subnet: 15.235.224.0/24
- Abuse Density: 0%
- Neighbors: 1 identified (15.235.224.64, Risk Score: 25)
- Classification: Low-abuse subnet
RELATIONSHIPS
IP is associated with hostname ns5031674.ip-15-235-224.net and network SD-ONENETWORK through DNS associations and network membership.
RECOMMENDED ACTIONS
Based on risk profile, the following firewall rules are recommended:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 15.235.224.155 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 15.235.224.155 drop` |
| nginx | `deny 15.235.224.155;` |
| pfSense | `15.235.224.155/32` |
| Cloudflare WAF | Block IP with expression: `ip.src eq 15.235.224.155` |
| AWS WAF | Add address: `15.235.224.155/32` |
---
ANALYST NOTES: This IP operates within a cloud hosting environment with moderate risk scoring. While no active threat indicators or known attacker signatures were observed, the IP is listed on two DNSBLs and returned HTTP 403 responses during scanning. The subnet abuse density is minimal (0%), suggesting this is an isolated instance rather than part of a coordinated campaign. Recommended blocking based on conservative risk posture; verification of business need may be warranted if legitimate use case exists.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH Singapore PTE. LTD |
| ASN | AS16276 |
| Network Name | SD-ONENETWORK |
| CIDR Block | 15.235.224.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ns5031674.ip-15-235-224.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ns5031674.ip-15-235-224.net |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 3/3 domains |
| DMARC | 0/3 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 3 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Apache/2.4.62 (AlmaLinux) OpenSSL/3.2.2 |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.7 |
๐ TLS Certificate
| SANs | be.play-studios.ai |
| Valid From | 2025-11-20T00:00:00+00:00 |
| Valid Until | 2026-12-19T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 394 days |
| Serial Number | 019EF654486FF507A57A529F720633E4 |
| Thumbprint | 65A5725B3F83983CA412414EAD4B701F71D4644D |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-11 17:58:04 UTC |
| Last Seen | 2026-08-30 13:55:40 UTC |
| Profile Built | 2026-08-30 15:24:11 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 28 |
Full dossier details are available via our API.