THREAT INTELLIGENCE BRIEFING
Target IP: 104.248.154.145/32
1. EXECUTIVE SUMMARY
IP 104.248.154.145 is a moderate-risk (50/100) address hosted on DigitalOcean infrastructure. The IP exhibits cloud computing characteristics with no active malicious indicators in current threat feeds. Geolocation data shows Singapore deployment, though historical observations indicate occasional US-based geolocation reports. The /24 subnet (104.248.154.0/24) is classified as clean with zero abuse density.
2. INFRASTRUCTURE PROFILE
- Organization: DigitalOcean, LLC (ASN 14061)
- Network Block: 104.248.0.0/16 (ARIN)
- Infrastructure Type: CloudCompute / Hosting Provider
- DNS Classification: No PTR records; no forward resolution detected
- Service Exposure: No open ports identified; TLS 1.3 observed in historical scans
- Server Banner: nginx/1.22.1 (historical)
3. THREAT INDICATORS
- Risk Score: 50 (Moderate)
- Blacklist Status: 0 blacklist entries
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- DNSBL Listings: 2 of 8 total lists (control plane data)
- Campaign Correlation: No known campaigns detected
4. GEOLOCATION ANALYSIS
Primary geolocation reports Singapore (SG). Historical observations show conflicting US-based reports (confidence 0.35). The control plane indicates stable routing within the 104.248.144.0/20 BGP prefix.
5. NEIGHBORHOOD CONTEXT
- Subnet: 104.248.154.0/24
- Abuse Density: 0
- Subnet Classification: Clean
- Neighbor Count: 0 active siblings
- No elevated threat indicators in surrounding /24 block
6. OBSERVATION HISTORY
- 15 historical observations recorded
- Recent activity includes SSH-2.0-Go and TLS 1.3 connections
- No ownership changes detected
- Threat persistence: 0 days; not persistently malicious
7. RECOMMENDED ACTIONS
Based on the risk score and firewall rule generation:
- iptables: `iptables -A INPUT -s 104.248.154.145 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 104.248.154.145 drop`
- Cloudflare WAF: Block IP with expression `ip.src eq 104.248.154.145`
- AWS WAF: Add `104.248.154.145/32` to whitelist/blacklist based on policy
8. INTELLIGENCE ASSESSMENT
This IP represents low-to-moderate risk within a legitimate cloud provider environment. The moderate risk score (50) likely reflects infrastructure hosting characteristics rather than active malicious behavior. SOC teams should monitor for escalation in threat indicators while maintaining awareness of geolocation inconsistencies for potential spoofing assessment. No immediate blocking is required unless additional contextual threat signals emerge.
9. DATA FRESHNESS
All data retrieved from IPDebrief intelligence platform. Control plane routing data current. Historical observations span recent monitoring period.
---
*End of Intelligence Briefing*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-104-248-0-0 |
| CIDR Block | 104.248.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.22.1 |
| HTTP Title | β |
| SSH Version | SSH-2.0-Go |
π TLS Certificate
CN=do.josi.my.id was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.| SANs | do.josi.my.id |
| Valid From | 2026-06-24T05:52:36+00:00 |
| Valid Until | 2026-09-22T05:52:35+00:00 (expired) |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 059D5C7DD668143BF0B2A8C2DBF2F54829C2 |
| Thumbprint | FE4AAA93C80B231AE8DC45B59A5FF90AA73065B4 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 22% | 6 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-08 16:29:46 UTC |
| Last Seen | 2026-08-27 10:00:24 UTC |
| Profile Built | 2026-08-29 04:37:31 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.