# IP INTELLIGENCE BRIEFING
Target: 104.248.183.81/32
Classification: LOW RISK / DEFENSIVE MONITORING
Date: 2026-06-21
Analyst: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
IP 104.248.183.81 is a DigitalOcean cloud infrastructure address (ASN 14061) classified as LOW RISK (Score: 25). The IP resolves to DNS hostname prod-barium-sfo2-25.do.binaryedge.ninja and is associated with cloud compute hosting in Santa Clara, California. No active threat indicators, blacklists, or malicious campaign signatures detected.
---
## OWNERSHIP & INFRASTRUCTURE
| Attribute | Value |
|---|---|
| ASN | 14061 |
| Organization | DigitalOcean, LLC |
| Network | DIGITALOCEAN-104-248-0-0 |
| CIDR Block | 104.248.0.0/16 |
| Infrastructure Type | Cloud Compute (Hosting) |
| Location | US (Santa Clara, CA) |
Assessment: Legitimate cloud infrastructure provider with established routing stability.
---
## NETWORK CLASSIFICATION
- Cloud Provider: Yes (DigitalOcean)
- CDN: No
- VPN/Proxy: No
- Tor Exit: No
- Hosting Service: Yes
- Open Ports: None detected
- Status: Firewalled / No Services
Network Role: Infrastructure hosting with no publicly accessible services.
---
## THREAT INTELLIGENCE
Risk Indicators
- Risk Score: 25/100 (Low)
- Abuse Confidence: None detected
- Blacklist Count: 0
- Known Attacker: False
- Spam Source: False
Control Plane Data
- DNSBL Listed: 1 of 8 lists
- Operator Score: 0.2609 (Basic)
- RPKI State: Not reported
- IRR Consistency: Not reported
Assessment: Minimal threat footprint with single DNSBL listing. No correlation to known attacker campaigns.
---
## DNS & RESOLUTION DATA
| Field | Value |
|---|---|
| PTR Hostname | prod-barium-sfo2-25.do.binaryedge.ninja |
| Forward Confirmed | Yes |
| Hosted Domain | binaryedge.ninja |
| Forward Resolution Count | 1 |
| SPF Record | Present |
| DMARC Record | Absent |
Assessment: Valid DNS resolution with email authentication (SPF only).
---
## OBSERVATION HISTORY
Total Observations: 22 signals across multiple timeframes
- 2026-06-21T05:39:55: Cloud infrastructure classification confirmed (confidence: 0.90)
- 2026-06-16T05:43:11: Basic operator classification (score: 0.3)
- 2026-06-12T03:59:27: Subnet abuse density analysis (mostly_clean classification)
Temporal Trends: Consistent cloud hosting classification with no degradation in stability. No malicious activity escalation observed.
---
## NEIGHBORHOOD ANALYSIS
- Subnet: 104.248.183.81/24
- Abuse Density: 1 (Low)
- Classification: Mostly Clean
- Active Siblings: 0
- Threat Siblings: 1 detected
Assessment: Subnet shows low abuse density. Single threat sibling detected but not correlated to target IP.
---
## GEOLOCATION VALIDATION
- Reported Location: US (Santa Clara, CA)
- Observed RTT: 86ms
- Minimum Possible RTT: 177.3ms (for 8863km distance)
- Geo Violation: YES (RTT discrepancy detected)
- Probe Count: 5
Assessment: Geolocation data shows RTT anomaly. Actual probe location differs from reported US coordinates by approximately 8,863km.
---
## RELATIONSHIP GRAPH
Total Relationships: 18
- DNS Associations: prod-barium-sfo2-25.do.binaryedge.ninja (multiple records)
- Network Associations: DIGITALOCEAN-104-248-0-0 (multiple records)
Assessment: Stable infrastructure with consistent DNS and network associations. No organizational or certificate relationships detected.
---
## RECOMMENDED ACTIONS
Current Risk Level: LOW
No specific firewall rules or blocking actions recommended. IP maintains legitimate cloud hosting profile with no active threat indicators.
Monitoring Recommendations:
- Monitor for service activation if currently firewalled
- Track DNSBL listing status
- Continue observation of geolocation anomalies
---
## INTELLIGENCE CONCLUSION
IP 104.248.183.81 represents a legitimate DigitalOcean cloud infrastructure address with low risk profile. The DNS hostname indicates association with binaryedge.ninja infrastructure. No malicious activity, blacklisting, or campaign correlations detected. The geolocation RTT anomaly warrants monitoring but does not indicate active exploitation. Recommended status: DEFENSIVE MONITORING.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-104-248-0-0 |
| CIDR Block | 104.248.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | prod-barium-sfo2-25.do.binaryedge.ninja |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | prod-barium-sfo2-25.do.binaryedge.ninja |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 34% | 2 | 3 |
| Overall | 23% | 9 | 14 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-30 17:00:29 UTC |
| Last Seen | 2026-06-29 07:50:14 UTC |
| Profile Built | 2026-06-29 13:51:30 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.