# IP Intelligence Briefing: 104.248.0.82/32
Classification: Moderate Risk - Cloud Infrastructure
Date: August 13, 2026
Analyst: IPDebrief Intelligence
---
## Executive Summary
IP 104.248.0.82 is a DigitalOcean cloud compute instance located in Clifton, New Jersey, operating under Cloudways hosting platform (cloudwaysapps.com). The IP presents a moderate risk profile (60/100) with no confirmed malicious indicators, though it demonstrates one DNSBL listing and exhibits elevated risk scores warranting enhanced monitoring.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **IP Address** | 104.248.0.82/32 |
| **Risk Score** | 60 (Moderate Risk) |
| **Organization** | DigitalOcean, LLC |
| **ASN** | 14061 |
| **CIDR Block** | 104.248.0.0/16 |
| **Geolocation** | US, New Jersey, Clifton |
| **Infrastructure Type** | CloudCompute |
| **DNS Host** | 1656134.cloudwaysapps.com |
| **Server Software** | nginx |
| **TLS Issuer** | Sectigo Public Server Authentication CA |
---
## Observed Services
- Port 80/tcp: HTTP
- Port 443/tcp: HTTPS (HTTP/2 enabled)
- Port 22/tcp: SSH (OpenSSH_9.2p1 Debian)
TLS certificate validates for *.cloudwaysapps.com domain, indicating legitimate Cloudways application hosting infrastructure.
---
## Threat Intelligence Assessment
Risk Factors
- Risk Score: 60/100 (Moderate)
- DNSBL Listings: 1 of 8 total lists
- Abuse Density: 0 (clean subnet)
- Known Campaigns: None detected
- Tor/Proxy/VPN: Not identified
Negative Indicators
- One DNSBL listing detected via control plane data
- Route stability marked as false
- HSTS header not configured
- No HSTS, CAA, or referrer policy headers present
Positive Indicators
- No known attacker or spam source indicators
- No Tor exit node status
- No association with known threat campaigns
- Subnet classification: clean
- Inherited risk: 0
---
## Observation History
Analysis of 21 signal observations reveals:
- Most recent probe: 2026-08-13T03:20:57 UTC
- Historical HTTP probe (2026-08-06): Status code 403 (Forbidden)
- Server response time: 464ms
- No observed threat persistence
- No correlated malicious IPs detected
The IP demonstrates stable ownership with no recent threat activity escalation.
---
## Neighborhood Analysis
Subnet 104.248.0.0/24 assessment:
- Abuse Density: 0 (clean)
- Total Siblings: 2
- Threat Siblings: 0
Neighbor IP: 104.248.0.244
- Risk Score: 25 (Low)
- Authority Score: 50
The /24 subnet shows minimal abuse activity, with the target IP as the only notable risk point.
---
## Recommended Actions
Monitoring
- Increase logging verbosity for traffic from 104.248.0.82
- Review recent activity and connection patterns
- Monitor for escalation in risk indicators
Firewall Rules (if blocking required)
```bash
# iptables
iptables -A INPUT -s 104.248.0.82 -j DROP
# nftables
nft add rule inet filter input ip saddr 104.248.0.82 drop
```
WAF Rules
```nginx
# nginx
deny 104.248.0.82;
# Cloudflare WAF
Block 104.248.0.82 β IPDebrief risk score 60
Filter: ip.src eq 104.248.0.82
```
---
## Intelligence Narrative
The target IP operates within legitimate DigitalOcean infrastructure hosting Cloudways applications. The moderate risk score (60/100) stems primarily from a single DNSBL listing and absence of security headers (HSTS, CAA, referrer policy), which are common on application hosting environments. No active threat indicators, known campaigns, or malicious behavior have been observed. The subnet demonstrates clean abuse density with no threat correlations.
Recommendation: Enhanced monitoring advised due to elevated risk score. Blocking may be considered based on organization-specific threat tolerances, though the IP shows characteristics of legitimate application hosting. Correlate with internal logs to determine if the DNSBL listing is relevant to observed traffic patterns.
---
*Generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
| Honeypot | Trap endpoint probes | 1 |
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-104-248-0-0 |
| CIDR Block | 104.248.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 1656134.cloudwaysapps.com |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 1656134.cloudwaysapps.com |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u10 |
π TLS Certificate
| SANs | *.cloudwaysapps.comcloudwaysapps.com |
| Valid From | 2026-03-24T00:00:00+00:00 |
| Valid Until | 2026-09-08T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 168 days |
| Serial Number | 009B708F987840C872F8BA3107B1BE80B7 |
| Thumbprint | 6C279C136F317BAEDEEEEA2E6CD5AABC7627E2E2 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 35% | 2 | 3 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 17% | 1 | 1 |
| Overall | 26% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-02 01:02:48 UTC |
| Last Seen | 2026-08-13 03:19:59 UTC |
| Profile Built | 2026-08-13 03:25:43 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.