# IP Intelligence Briefing: 104.248.122.202/32
Classification: Cloud Infrastructure Asset
Report Date: 2026-06-20
Analyst: IPDebrief Intelligence Team
---
## Executive Summary
IP 104.248.122.202 is a DigitalOcean cloud infrastructure address located in North Bergen, NJ (US). The asset presents LOW RISK (Score: 25/100) with no active threat indicators. The IP is firewalled with no open services detected, though one historical signal flagged VPN/proxy characteristics.
---
## Network Profile
| Attribute | Value |
|---|---|
| **Organization** | DigitalOcean, LLC |
| **ASN** | AS14061 |
| **Infrastructure Type** | Cloud Compute |
| **Service Purpose** | Firewalled / No Services |
| **Geolocation** | US, New Jersey, North Bergen |
| **BGP Prefix** | 104.248.112.0/20 |
---
## Risk Assessment
- Overall Risk Score: 25/100 (Low Risk)
- Abuse Confidence Score: Not elevated
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 total lists
- Known Campaigns: None identified
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
---
## Service & Network Behavior
- Open Ports: None detected
- DNS Resolution: No forward resolution
- PTR Hostnames: None
- TLS/HTTP Services: None detected
- Network Role: Cloud hosting environment (firewalled)
---
## Historical Observations
Total Signals: 17 observations tracked
Recent Activity:
- 2026-06-20: VPN/proxy type identified (Risk: 66, Confidence: 85%)
- 2026-06-15: Operator score "Minimal" (Score: 0.1304, Confidence: 30%)
- 2026-06-08: US geolocation confirmed via multi-signal inference
Temporal Trends:
- Threat observation count: 1
- Is persistently malicious: No
- Ownership changes: 0
---
## Network Neighborhood Analysis
Subnet: 104.248.122.0/24
- Abuse Density: 0
- Risk Classification: Mostly clean
- Threat Siblings: 1
- Active Siblings: 0
- Inherited Risk: 2/100
No adjacent IPs flagged as high-risk threats. Subnet maintains low abuse profile.
---
## Threat Indicators
- Active Threats: None detected
- Campaign Correlations: 0
- Certificate Matches: 0
- Banner Matches: 0
---
## Recommended Security Actions
Current Recommendations: None required
Firewall Rules: No specific blocking rules generated based on risk profile.
SOC Analyst Notes:
- Monitor for VPN/proxy activity changes if this IP is used in legitimate services
- The single DNSBL listing warrants periodic review
- No immediate threat mitigation required; maintain standard monitoring
- Consider context of deployment environment when evaluating VPN/proxy signal
---
## Intelligence Context
This IP represents standard DigitalOcean cloud infrastructure with firewalled configuration. The single VPN/proxy signal from June 20 may indicate legitimate remote access configuration or shared infrastructure. Low abuse density in the /24 subnet supports benign classification. No evidence of malicious activity or campaign participation.
Recommendation: Continue routine monitoring; no active threat response required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-17 15:11:26 UTC |
| Last Seen | 2026-06-28 05:02:30 UTC |
| Profile Built | 2026-06-28 23:07:16 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.