## IP INTELLIGENCE BRIEFING
Target: 104.248.219.79/32
Date: 2026-08-06
Classification: Cloud Infrastructure Node
Risk Assessment: LOW RISK (Score: 25/100)
---
EXECUTIVE SUMMARY
The target IP is a DigitalOcean cloud compute instance located in Santa Clara, California (US). The address resolves to a "binaryedge.ninja" infrastructure hostname, consistent with security research tooling. No active malicious indicators detected. The IP exhibits minimal threat surface with zero known attacker reputation and no confirmed abuse history.
---
INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| **Provider** | DigitalOcean |
| **ASN** | 14061 |
| **BGP Prefix** | 104.248.208.0/20 |
| **Location** | US, California, Santa Clara |
| **Infrastructure Type** | CloudCompute |
| **Network Role** | Cloud Hosting (Firewalled / No Services) |
| **DNSSEC** | Valid |
| **Tor Exit Node** | No |
---
DNS & HOSTING INTELLIGENCE
Resolved Hostname: prod-xenon-sfo2-5.do.binaryedge.ninja
Domain: binaryedge.ninja
Forward Resolution: Confirmed (1 record)
The DNS association links this IP to the "binaryedge.ninja" infrastructure, a known security research platform. This is consistent with legitimate security operations tooling rather than malicious activity.
---
THREAT INDICATORS
| Indicator | Status |
|---|---|
| **Abuse Confidence Score** | Not applicable |
| **Known Attacker** | False |
| **Spam Source** | False |
| **Blacklist Count** | 0 |
| **DNSBL Listings** | 1 of 8 lists |
| **Threat Feeds** | None |
| **Known Campaigns** | None |
Assessment: No active threat indicators. The single DNSBL listing represents minimal exposure.
---
NEIGHBORHOOD ANALYSIS
Subnet: 104.248.219.79/24
Abuse Density: 0%
Neighbor Count: 0
Threat Siblings: 0
The /24 subnet shows zero abuse activity and no neighboring threat indicators. This isolated profile suggests either a dedicated instance or limited subnet utilization.
---
OBSERVATION HISTORY
Total Observations: 11 signals
Most Recent: 2026-08-06T01:35:01 UTC
Key historical signals:
- Cloud infrastructure classification (confidence: 0.90)
- US geolocation inference (confidence: 0.65)
- Operator score: 0.2609 (Basic classification)
- DNSBL listing with max severity "high" (single occurrence)
Temporal Stability: No ownership changes detected. No persistently malicious behavior observed.
---
RECOMMENDED ACTIONS
Risk Score: 25/100
Recommended Action: MONITOR (No immediate blocking required)
Firewall Rules: No specific blocking rules recommended based on current risk profile.
SOC Considerations:
1. The IP resolves to security research infrastructure (binaryedge.ninja)
2. Low risk score with no active threat indicators
3. Standard monitoring recommended; no immediate mitigation required
4. Correlate with any observed traffic patterns for context
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-104-248-0-0 |
| CIDR Block | 104.248.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | prod-xenon-sfo2-5.do.binaryedge.ninja |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | prod-xenon-sfo2-5.do.binaryedge.ninja |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 2 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 17% | 1 | 1 |
| Overall | 22% | 9 | 11 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-31 07:29:45 UTC |
| Last Seen | 2026-08-13 01:30:03 UTC |
| Profile Built | 2026-08-13 01:45:00 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.