# IP Intelligence Briefing: 143.198.179.104
Classification: Moderate Risk | Risk Score: 50/100
Date: Current Intelligence Assessment
## Executive Summary
IP address 143.198.179.104 is a DigitalOcean cloud host operating a web service (nginx/1.24.0) with a moderate risk profile. The IP is associated with survey infrastructure (survey06.hackertarget.io) and shows no persistent malicious behavior. While currently classified as clean, the moderate risk score warrants monitoring.
## Infrastructure Profile
- Organization: DigitalOcean, LLC (ASN: 14061)
- Network Block: 143.198.0.0/16
- Location: United States, New Jersey (North Bergen)
- Infrastructure Type: Cloud Compute (isCloud: true, isHosting: true)
- DNS Association: survey06.hackertarget.io
## Threat Assessment
Current Risk Status: Moderate Risk (Score: 50)
Threat Indicators:
- No known attacker indicators
- Not a Tor exit node
- No spam source classification
- Zero known campaign associations
- Blacklist status: Listed on 2 of 8 DNSBL sources checked
Network Context:
- Subnet abuse density: 0 (clean classification)
- No threat siblings detected in /24 neighborhood
- No active siblings in /24
- No inherited risk from network peers
## Behavioral Analysis
Observation History (22 total signals):
- Most recent observations: August 13, 2026
- Consistent classification: "clean" across recent signals
- No persistent malicious activity detected
- Threat persistence days: 0
- No ownership changes detected
Technical Fingerprint:
- Server: nginx/1.24.0 (Ubuntu)
- HTTP Version: 1.1
- Status Code: 200
- Response Time: ~51-63ms
## Operational Context
The DNS hostname (survey06.hackertarget.io) suggests this IP may be part of a scanning or survey infrastructure. The "hackertarget.io" domain typically correlates with vulnerability scanning activities. While the IP itself is not flagged as malicious, its operational context in a survey infrastructure environment warrants awareness.
## Recommended Actions
Immediate Mitigation:
```bash
# iptables
iptables -A INPUT -s 143.198.179.104 -j DROP
# nftables
nft add rule inet filter input ip saddr 143.198.179.104 drop
```
WAF Rules:
- Cloudflare: Block IP with expression `ip.src eq 143.198.179.104`
- AWS WAF: Add `143.198.179.104/32` to blocklist
## Analyst Notes
1. Risk Score Interpretation: Score of 50 indicates moderate risk. The absence of threat indicators suggests this may be legitimate infrastructure rather than active malicious actor.
2. Monitoring Recommendation: Continue monitoring for changes in DNS associations or risk score escalation. The survey infrastructure context provides useful context for threat correlation.
3. Decision Framework: Given the moderate risk classification and lack of persistent malicious indicators, consider blocking this IP in conjunction with other threat intelligence sources. The survey hostname context supports a cautious approach.
4. No Immediate Escalation: No evidence of active exploitation, data exfiltration, or command-and-control activity associated with this IP.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-143-198-0-0 |
| CIDR Block | 143.198.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | survey06.hackertarget.io |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | survey06.hackertarget.io |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| Closed Ports | 22, 25, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 35% | 2 | 3 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 29% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-03 23:38:27 UTC |
| Last Seen | 2026-08-13 05:32:51 UTC |
| Profile Built | 2026-08-13 05:55:02 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.