# IP Intelligence Briefing: 104.236.91.115/32
Classification: Low Risk / Cloud Infrastructure
Date: Current Assessment
Risk Score: 25/100
---
## Executive Summary
IP 104.236.91.115 is identified as a DigitalOcean cloud compute instance hosted in New York, US. The asset presents a low risk profile with no active threat indicators. No actionable security recommendations are warranted at this time.
---
## Infrastructure Profile
Ownership & Provider:
- Organization: DigitalOcean, LLC
- ASN: 14061
- BGP Prefix: 104.236.64.0/18
- Infrastructure Type: Cloud Compute
- Hosting Classification: Yes
- Contact: abuse@digitalocean.com
Geolocation:
- Country: United States (US)
- Region: US-NY (New York)
- Coordinates: Latitude/longitude unavailable
- Timezone: America/New_York
- GPS Validation: Inconsistent (geoPlausible: false)
Network Services:
- Open Ports: None detected
- TLS Certificate: Not configured
- HTTP Services: Not detected
- Service Purpose: Firewalled / No Services
---
## Threat Assessment
Current Risk Indicators:
- Reputation: Low Risk
- Abuse Confidence Score: Not elevated
- Threat Indicators: None detected
- Known Attacks: False
- Spam Source: False
- Tor Exit Node: False
Blacklist Status:
- DNSBL Listings: 1 of 8 total lists
- Threat Feeds: None
- Known Campaigns: None
Behavioral Signals:
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: 0
---
## Observation History
Signal Count: 14 observations recorded
Timeframe: June 2026
Key Observations:
- Organizational registration signals consistently identify DigitalOcean, LLC
- RIR registration (ARIN) confirmed across multiple observations
- Operator score: 0.1304 (Minimal)
- No significant changes in threat posture observed
- Ownership stability: No ownership changes recorded
Temporal Analysis:
- Threat Persistence Days: 0
- Observation Count: 0 (persistent malicious activity)
- Is Persistently Malicious: False
---
## Neighborhood Analysis
Subnet: 104.236.91.0/24
- Neighbor Count: 0
- Abuse Density: 0
- High Risk Neighbors: 0
- Medium Risk Neighbors: 0
- Low Risk Neighbors: 0
Inherited Risk: None (no sibling threat correlation)
---
## Relationship Graph
Connected Entities: None detected
- Subnet Links: None
- Hostname Links: None
- Organization Links: None
- Certificate Links: None
---
## Recommended Actions
Current Status: No specific firewall rules or security actions recommended.
Rationale:
- Risk score (25) falls within acceptable operational thresholds
- No active threat indicators present
- Infrastructure is properly classified as cloud compute with no exposed services
- Historical data shows consistent, benign operational patterns
Suggested Monitoring:
- Continue standard traffic monitoring
- No immediate blocking or allowlisting required
- Review DNSBL listing status if security policies are strict
---
## Intelligence Assessment
IP 104.236.91.115 represents standard cloud infrastructure with no evidence of malicious activity. The absence of threat indicators, combined with the cloud hosting classification and lack of active services, indicates this IP serves benign infrastructure purposes. The single DNSBL listing appears to be a false positive or standard compliance marker rather than active abuse.
Recommended Handling: Allow traffic with standard logging. No special treatment required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-104-236-0-0 |
| CIDR Block | 104.236.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 17% | 1 | 1 |
| routing | 17% | 1 | 1 |
| services | 17% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 17% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 11% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-14 14:11:06 UTC |
| Last Seen | 2026-06-21 21:52:33 UTC |
| Profile Built | 2026-06-21 21:59:12 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 19 |
Full dossier details are available via our API.