# IP Intelligence Briefing: 140.248.75.191
Classification: CDN Infrastructure (Moderate Risk)
Report Date: July 2026
Intel Source: IPDebrief Threat Intelligence Platform
---
## Executive Summary
IP address 140.248.75.191 is an edge infrastructure address belonging to Fastly, Inc. (ASN 54113), operating within the SKYCA-3 CDN network (140.248.0.0/16). The IP presents a moderate risk profile (Score: 50) with no active threat indicators. The address is associated with CDN infrastructure services and shows consistent operational behavior with minimal malicious activity.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **IP Address** | 140.248.75.191/32 |
| **Provider** | Fastly, Inc. |
| **ASN** | 54113 |
| **Network** | SKYCA-3 (140.248.0.0/16) |
| **Geolocation** | US (Frankfurt am Main, DE) |
| **Infrastructure Type** | CDN (Content Delivery Network) |
| **Risk Score** | 50 (Moderate Risk) |
| **Open Ports** | None detected |
| **Service Status** | Firewalled / No Services |
---
## Threat Assessment
Active Threat Indicators
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0
- Known Campaigns: None detected
DNSBL Status
- Listed Count: 2 out of 8 total threat feeds
- Status: Limited reputation concerns
Network Classification
- Provider: Fastly (CDN)
- Cloud Infrastructure: No
- Anycast: No
- Mobile/Residential: No
---
## Neighborhood Analysis (140.248.75.0/24)
| Metric | Value |
|---|---|
| **Subnet Abuse Density** | 0 (Clean) |
| **Total Siblings** | 12 IPs scanned |
| **Active Siblings** | 1 |
| **Threat Siblings** | 0 |
| **Risk Distribution** | High: 0, Medium: 1, Low: 4 |
Notable Neighbors
- 140.248.75.96: Risk Score 50 (Same risk profile)
- 140.248.75.129: Risk Score 25 (Medium-low)
- 140.248.75.151: Risk Score 25 (Medium-low)
The subnet demonstrates minimal abuse activity, consistent with legitimate CDN infrastructure operations.
---
## Historical Observation Trends
Observation Period: 16 recorded observations
Key Findings:
- Consistent US geolocation reporting
- Minimal operator score (0.1304) in recent assessments
- No persistent malicious behavior detected
- Neighborhood classification remained "clean" across observation period
- Limited threat persistence indicators
---
## Related Entities
Network Relationships:
- SKYCA-3 (Same Network)
---
## Recommended Security Actions
Based on the moderate risk profile (Score: 50), the following defensive measures are recommended:
Firewall Blocking Rules
```bash
# iptables
iptables -A INPUT -s 140.248.75.191 -j DROP
# nftables
nft add rule inet filter input ip saddr 140.248.75.191 drop
# nginx
deny 140.248.75.191;
```
WAF Integration
Cloudflare WAF:
```json
{
"description": "Block 140.248.75.191 — IPDebrief risk score 50",
"action": "block",
"filter": {
"expression": "ip.src eq 140.248.75.191"
}
}
```
AWS WAF:
```json
{
"Addresses": ["140.248.75.191/32"],
"Description": "IPDebrief risk 50"
}
```
---
## Intelligence Conclusion
IP 140.248.75.191 represents legitimate CDN infrastructure from Fastly with no evidence of active exploitation or malicious activity. The moderate risk score reflects standard CDN operational patterns rather than adversarial behavior. Security teams may consider blocking this IP if it appears in suspicious connection logs, but such action should be validated against contextual threat intelligence. The IP's association with Fastly CDN and clean neighborhood metrics support treating this as infrastructure rather than a threat source.
Recommendation: Monitor for anomalous behavior; consider blocking only if observed in context of malicious activity patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Fastly, Inc. |
| ASN | AS54113 |
| Network Name | SKYCA-3 |
| CIDR Block | 140.248.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting — Infrastructure provider without advanced routing |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS54113 |
| Network Prefix | 140.248.75.0/24 |
| Route mapping | Found |
| Certificates in transparency logs | 0 certificates |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 17% | 2 | 3 |
| reputation | 19% | 1 | 2 |
| geolocation | 24% | 2 | 3 |
| Overall | 20% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-05 11:42:31 UTC |
| Last Seen | 2026-08-27 08:31:16 UTC |
| Profile Built | 2026-08-29 05:01:32 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 140.248.75.191
Who owns the IP address 140.248.75.191?
140.248.75.191 is registered to Fastly, Inc.. The address falls within the 140.248.0.0/16 network block. Registration is held at ARIN.
Where is 140.248.75.191 located?
Geolocation data places 140.248.75.191 in Frankfurt am Main, Hesse, United States. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 140.248.75.191 malicious or safe?
140.248.75.191 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
Is 140.248.75.191 a VPN, proxy, or data center address?
140.248.75.191 is classified as a content delivery network based on network ownership and behavioural analysis.