# THREAT INTELLIGENCE BRIEFING
IP Address: 104.248.144.33/32
Date: 2026-07-31
Classification: Moderate Risk
---
## 1. EXECUTIVE SUMMARY
IP 104.248.144.33 is registered to DigitalOcean, LLC (ASN 14061) and operates as a cloud compute infrastructure endpoint. The address exhibits a moderate risk score of 50 with no active threat indicators, blacklist associations, or observed malicious activity. The IP is geolocated to Singapore with cloud hosting infrastructure.
---
## 2. OWNERSHIP AND INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| **Organization** | DigitalOcean, LLC |
| **ASN** | 14061 |
| **CIDR Block** | 104.248.0.0/16 |
| **Geolocation** | Singapore (SG) |
| **Infrastructure Type** | Cloud Compute |
| **Hosting Status** | Enabled |
| **Service Purpose** | Firewalled / No Services |
The IP operates within DigitalOcean's cloud infrastructure with no open ports detected. DNS reverse resolution is unconfirmed with no PTR hostnames.
---
## 3. THREAT ASSESSMENT
Overall Risk Score: 50 (Moderate)
Threat Indicators:
- No threat indicators observed
- Blacklist count: 0
- Abuse confidence score: Not assessed
- Is known attacker: No
- Is spam source: No
- Tor exit node: No
DNSBL Status: Listed on 2 of 8 DNS blacklist sources. This may indicate historical activity or false positives.
Control Plane: BGP prefix 104.248.144.0/20 with minimal operator score (0.1304). Route stability is not confirmed.
---
## 4. NEIGHBORHOOD ANALYSIS
Subnet: 104.248.144.33/24
Abuse Density: 0%
Total Neighbors: 1
Neighbor Summary:
- 104.248.144.24: Risk Score 25 (Low)
- Risk Distribution: 1 low, 0 medium, 0 high
The /24 subnet shows minimal abuse activity with low-risk neighbor activity.
---
## 5. OBSERVATION HISTORY
Total Observations: 13 signals
Recent Activity: 2026-07-31
Key observations from the most recent monitoring period:
- Ownership signals consistently identify DigitalOcean, LLC
- Geolocation signals show Singapore with distance validation (10,369.3 km)
- ICMP validation blocked due to ICMP blocking
- No ownership changes detected
- No persistent malicious activity observed
---
## 6. RELATIONSHIP GRAPH
Relationship Count: 3
- All relationships classified as "Same Network" (DIGITALOCEAN-104-248-0-0)
- No external entity relationships detected (no hostnames, organizations, or certificates linked)
---
## 7. RECOMMENDED ACTIONS
Risk Score: 50 (Moderate)
The following firewall rules are recommended based on risk profile:
| Platform | Rule |
|---|---|
| **iptables** | `iptables -A INPUT -s 104.248.144.33 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 104.248.144.33 drop` |
| **nginx** | `deny 104.248.144.33;` |
| **pfSense** | `104.248.144.33/32` |
| **Cloudflare WAF** | Block with expression: `ip.src eq 104.248.144.33` |
| **AWS WAF** | Add to address set: `104.248.144.33/32` |
---
## 8. ANALYST NOTES
- False Positive Potential: DNSBL listings (2/8) may represent historical activity or false positives given the lack of active threat indicators.
- Cloud Infrastructure Context: As a DigitalOcean cloud compute endpoint with firewalled/no-services status, this IP may be legitimately used for legitimate cloud services or may be abused for transient malicious activity.
- Monitoring Recommendation: Continue monitoring for changes in DNSBL status or emergence of threat indicators. No immediate blocking required pending additional threat intelligence correlation.
---
Report Generated: 2026-07-31
Data Source: IPDebrief Intelligence Platform
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-104-248-0-0 |
| CIDR Block | 104.248.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-30 17:10:59 UTC |
| Last Seen | 2026-08-13 00:45:10 UTC |
| Profile Built | 2026-08-13 00:55:10 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.