# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 51.75.127.195/32
Date: 2026-06-27
Classification: MODERATE RISK
Risk Score: 40/100
---
## EXECUTIVE SUMMARY
IP 51.75.127.195 is a cloud compute VPS instance hosted by OVH SAS in France. The address exhibits moderate risk characteristics with evidence of prior abuse activity. Current risk score of 40 indicates reduced threat activity compared to previous observations showing a score of 65. No active services are detected; the host appears firewalled.
---
## OWNERSHIP & GEOLOCATION
| Field | Value |
|---|---|
| ASN | 16276 (OVH SAS) |
| Organization | OVH SAS |
| Country | France (FR) |
| RIR | ARIN |
| Network Type | Cloud Compute / Hosting |
| DNS | vps-bdda127.195.vps.ovh.net |
Geolocation data indicates France with 500km accuracy radius. Multiple geolocation sources confirm consensus location.
---
## THREAT INDICATORS
Blacklist Status:
- Total Blacklist Listings: 8
- DNSBL Listed: 2
- Maximum Severity: HIGH
- Recent Listings: 2026-06-27 (confidence 0.85)
Threat Classification:
- Is Tor Exit Node: NO
- Is Known Attacker: NO
- Is Spam Source: NO
- Active Threat Feeds: NONE
Services:
- Open Ports: NONE
- TLS Certificate: NONE
- HTTP Banner: NONE
- Status: Firewalled / No Services
---
## TEMPORAL ANALYSIS
Risk Trend: DECREASING
- 2026-06-19: Risk Score 65/100 (HIGH RISK)
- 2026-06-27: Risk Score 40/100 (MODERATE RISK)
Observation History: 21 total observations recorded
- Most recent activity: 2026-06-27T21:48:31 UTC
- Threat persistence: 0 days
- Is Persistently Malicious: NO
---
## NEIGHBORHOOD ANALYSIS
Subnet: 51.75.127.0/24
- Abuse Density: 0.0
- Classification: MOSTLY CLEAN
- Total Siblings: 256
- Active Siblings: 0
- Threat Siblings: 1
---
## NETWORK RELATIONSHIPS
| Type | Target | Count |
|---|---|---|
| DNS Association | vps-bdda179c.vps.ovh.net | 3 |
| Same Network | VPS-GRA6 (OVH) | 2 |
| **Total Relationships** | **49** |
---
## RECOMMENDED ACTIONS
Risk Score: 40/100
Action Level: MONITOR / CONDITIONAL BLOCK
Firewall Rules (Recommended)
iptables:
```
iptables -A INPUT -s 51.75.127.195 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 51.75.127.195 drop
```
Cloudflare WAF:
```json
{
"description": "Block 51.75.127.195 โ IPDebrief risk score 40",
"action": "block",
"filter": {
"expression": "ip.src eq 51.75.127.195"
}
}
```
AWS WAF:
```json
{
"Addresses": ["51.75.127.195/32"],
"Description": "IPDebrief risk 40"
}
```
---
## INTELLIGENCE ASSESSMENT
This IP address represents a moderate threat requiring conditional blocking. Historical evidence shows the address was previously associated with higher-risk activity (score 65), though current risk has decreased. The absence of open services and active threat feeds suggests the host may have been repurposed or the threat actor reduced activity.
SOC Analyst Guidance:
- Monitor for reactivation of services
- Review historical blacklist listings for context
- Consider blocking due to prior high-severity blacklist associations
- No immediate incident correlation to known campaigns
---
*Data Source: IPDebrief Intelligence Platform*
*Last Updated: 2026-06-27*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH SAS |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vps-bdda179c.vps.ovh.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vps-bdda179c.vps.ovh.net |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 20% | 2 | 3 |
| reputation | 21% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 22% | 9 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-12 15:48:21 UTC |
| Last Seen | 2026-06-27 21:48:36 UTC |
| Profile Built | 2026-06-28 15:53:32 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.