IPDebrief

151.80.61.151

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# Intelligence Briefing: 151.80.61.151/32

Classification: MODERATE RISK | Last Updated: 2026-06-14

---

## Executive Summary

IP 151.80.61.151 is a cloud-hosted infrastructure endpoint associated with OVH SAS (ASN 16276), located in Roubaix, France. The IP demonstrates moderate risk (Score: 50) due to DNSBL listings, though the surrounding /24 subnet remains classified as "mostly_clean" with zero threat siblings. No active malicious campaigns or correlation with known attacker infrastructure have been identified.

---

## Infrastructure Profile

AttributeValue
**Organization**OVH SAS
**ASN**16276
**Country**France (FR)
**City**Roubaix
**Infrastructure Type**Cloud Compute / Hosting
**Network Role**Single-Service Host
**Risk Score**50 (Moderate)

---

## Technical Observations

DNS Resolution:

Service Enumeration:

---

## Threat Indicators

IndicatorStatus
**DNSBL Listings**2 of 8 total lists
**Known Attacker**No
**Tor Exit Node**No
**Spam Source**No
**Active Campaigns**None
**Blacklist Count**0

Control Plane:

---

## Temporal Analysis

Observation History:

The IP has demonstrated persistent ownership with no recent changes to infrastructure ownership.

---

## Neighborhood Assessment

Subnet: 151.80.61.0/24

The surrounding subnet shows no elevated threat density, suggesting this IP operates in isolation without coordinated neighbor activity.

---

## Relationship Graph

Total Relationships: 65

---

## Recommended Actions

ActionPriority
Monitor DNSBL listing changesMedium
Allow SSH access if legitimate business need existsLow
Block if outbound traffic to known malicious destinationsMedium
Continue monitoring for new campaign indicatorsLow

---

## Intelligence Notes

1. Cloud Environment: This IP operates within OVH's cloud infrastructure, which may limit investigation capabilities.

2. DNSBL Presence: The 2 DNSBL listings warrant monitoring but do not indicate active malicious activity.

3. Geolocation Consistency: 5 probe signals confirm France location with ~307km validation distance.

4. No Campaign Correlation: Zero matches with known threat campaigns or correlated malicious IPs.

Status: Monitor | Confidence: High

---

*This briefing is based on IPDebrief intelligence data as of 2026-06-14. All data should be validated against internal threat intelligence sources before operational decision-making.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ซ๐Ÿ‡ท France
RegionHDF
CityRoubaix
TimezoneEurope/Paris
Latitude50.70
Longitude3.18

๐Ÿข Ownership & Registration

OrganizationOVH SAS
ASNAS16276
Network Nameโ€”
CIDR Blockโ€”
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRvps-5d95afd4.vps.ovh.net
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesvps-5d95afd4.vps.ovh.net

๐Ÿ” DNS Hygiene

Hygiene Score80% (Excellent)
SPF1/2 domains
DMARC1/2 domains
FCrDNSVerified
DNSSECValid
CAANot configured
Domains Checked2 domains

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
8080http-alttcpโ€”
Closed Ports22, 25, 3389, 8443 (3 open / 7 scanned)
Servernginx/1.18.0 (Ubuntu)
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
CN=serp.seniatna.tn
Issued by CN=YR2, O=Let's Encrypt, C=US
Self-signed: No
SANsserp.seniatna.tn
Valid From2026-06-05T09:03:23+00:00
Valid Until2026-09-03T09:03:22+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period89 days
Serial Number05980890E85177E724215F6C7CA05AFFA8C4
ThumbprintC9E3DB3E4858F47B72CA06ABFCAC08AA429461EF

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
28%
24
routing
13%
11
services
34%
23
ownership
24%
23
reputation
26%
13
geolocation
37%
23
Overall27%1017
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-09 11:33:37 UTC
Last Seen2026-06-27 15:20:53 UTC
Profile Built2026-06-28 09:25:44 UTC
Data FreshnessLive
Signal Types24
Total Observations31
๐Ÿ” 24 signal types ยท 31 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.