# IP Intelligence Briefing: 143.110.181.226
## Executive Summary
IP 143.110.181.226 presents a moderate risk profile (score: 65/100) associated with DigitalOcean cloud infrastructure. The IP demonstrates proxy/VPN behavior in recent observations and shows geographic inconsistencies between reported locations. No active threat indicators or known campaign associations detected. Recommended action: implement logging monitoring and consider blocking based on organizational policy.
## Ownership and Infrastructure
- ASN: AS14061 (DigitalOcean, LLC)
- Network Block: 143.110.128.0/17 (DIGITALOCEAN-143-110-128-0)
- Infrastructure Type: Cloud compute provider
- Geolocation: Bengaluru, Karnataka, India (multiple sources report India; one source reported US)
- Service Status: No open ports detected; classification indicates "Firewalled / No Services"
## Risk Assessment
| Metric | Value |
|---|---|
| **Risk Score** | 65/100 (Moderate Risk) |
| **Provider Score** | 0/100 |
| **Authority Score** | 0/100 |
| **DNSBL Listings** | 3 of 8 lists |
| **Abuse Confidence** | Not scored |
## Threat Indicators
- Proxy/VPN Detection: Confirmed in recent observations (proxy_type: VPN)
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0 (but DNSBL listed on 3 of 8 reputation lists)
- Threat Campaigns: None detected
- Known Attacks: No active indicators
## Neighborhood Analysis
- Subnet: 143.110.181.226/24
- Abuse Density: 0.0 (clean classification)
- Neighbor IP: 143.110.181.178 (risk score: 50/100)
- Threat Siblings: 0
- Active Siblings: 0
## Behavioral History
Analysis of 19 observations reveals:
- Recent activity concentrated on 2026-06-22 with proxy/VPN classification
- Risk scores ranged from 65-66 in recent observations
- Geographic data shows inconsistency (India vs US reports)
- No persistent malicious behavior detected
- Route stability shows recent changes (not stable for 30 days)
## Network Classification
- ISP: DigitalOcean
- Connection Type: Cloud infrastructure
- Mobile Carrier: N/A
- Proxy: Yes (recently detected)
- Hosting: Yes
- Tor/VPN: Proxy behavior confirmed
## Recommended Actions
Immediate
1. Increase logging verbosity for traffic from this IP
2. Review recent activity from 143.110.181.226 in SIEM/SOC tools
Firewall Rules
```bash
# iptables
iptables -A INPUT -s 143.110.181.226 -j DROP
# nftables
nft add rule inet filter input ip saddr 143.110.181.226 drop
# nginx
deny 143.110.181.226;
# pfSense
143.110.181.226/32
# Cloudflare WAF
ip.src eq 143.110.181.226 (action: block)
# AWS WAF
Addresses: 143.110.181.226/32
```
## Analyst Notes
The IP's proxy/VPN detection combined with DNSBL listings suggests potential misuse of cloud infrastructure for anonymization. Geographic inconsistencies between sources warrant monitoring. While no active attack indicators are present, the moderate risk score and proxy behavior justify enhanced logging and consideration of blocking based on threat level and organizational policy.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-143-110-128-0 |
| CIDR Block | 143.110.128.0/17 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 2 |
| routing | 17% | 1 | 1 |
| services | 17% | 1 | 1 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 17% | 1 | 1 |
| Overall | 21% | 8 | 10 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-16 12:25:55 UTC |
| Last Seen | 2026-06-22 00:22:06 UTC |
| Profile Built | 2026-06-22 00:30:19 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 19 |
Full dossier details are available via our API.