## IP INTELLIGENCE BRIEFING
Target: 146.190.139.80/32
Date: 2026-07-30
Classification: Moderate Risk
---
EXECUTIVE SUMMARY
IP 146.190.139.80 is a DigitalOcean cloud infrastructure address with an overall risk score of 65/100 (Moderate Risk). The IP shows no active threat indicators, no open services, and no open ports. While the risk score is elevated, the lack of active malicious behavior and clean neighborhood context suggest this may be a false positive or a legitimate infrastructure IP with historical reputation concerns.
---
OWNERSHIP & INFRASTRUCTURE
- Organization: DigitalOcean, LLC (ASN 14061)
- Network Block: 146.190.0.0/16 (DO-13)
- Geolocation: United States, California (Santa Clara region)
- Infrastructure Type: Cloud Compute
- Registration: ARIN registry
The IP is classified as cloud hosting infrastructure with no CDN, VPN, proxy, or Tor exit node characteristics.
---
THREAT ASSESSMENT
- Risk Score: 65/100
- Threat Indicators: None detected
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- DNSBL Listings: 3 of 8 lists
- Abuse Confidence Score: Not available
- Campaign Correlation: No matches
Key Findings:
- No open ports or active services detected
- No TLS certificates or HTTP services responding
- No known threat campaigns associated
- No evidence of persistent malicious behavior
---
NEIGHBORHOOD ANALYSIS
- Subnet: 146.190.139.80/24
- Abuse Density: 0% (Clean)
- Total Siblings: 2
- Active Siblings: 1
- Threat Siblings: 0
- Inherited Risk: 0
Adjacent IP: 146.190.139.182 (Risk Score: 25, Authority Score: 50)
The /24 subnet shows minimal abuse activity, with only one neighbor IP exhibiting low-risk characteristics.
---
OBSERVATION HISTORY
- Total Observations: 14 signals recorded
- Ownership Changes: 0
- Threat Persistence Days: 0
- Recent Activity: Consistent DigitalOcean ownership
The IP has demonstrated stable ownership with no recent changes. Geolocation signals indicate consistent US-based location with plausible coordinates.
---
NETWORK BEHAVIOR
- Service Purpose: Firewalled / No Services
- Connection Type: Cloud infrastructure
- BGP Prefix: 146.190.128.0/19
- Route Stability: Unstable (false)
- DNSSEC Valid: Yes
- Honeypot Hits: 0
- Enumeration Strikes: 0
---
RECOMMENDED ACTIONS
Priority: Moderate
1. Monitoring: Increase logging verbosity and review recent activity from this IP due to elevated risk score (65/100)
2. Firewall Considerations: Consider blocking at perimeter if this IP has been observed attempting unauthorized access
Recommended Firewall Rules:
- iptables: `iptables -A INPUT -s 146.190.139.80 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 146.190.139.80 drop`
- Cloudflare WAF: Block IP with description "IPDebrief risk score 65"
- AWS WAF: Add IP 146.190.139.80/32 to block list
---
INTELLIGENCE NARRATIVE
The IP address 146.190.139.80 represents DigitalOcean cloud infrastructure with no active malicious indicators. The elevated risk score of 65 appears to stem from historical DNSBL listings rather than current threat activity. The subnet context is clean with zero abuse density, and the single adjacent IP shows minimal risk. While no immediate threat is evident, the moderate risk classification warrants continued monitoring. The lack of open services and firewalled status suggests this IP is not currently being used for active attack operations. Correlation with other security signals is recommended before implementing blocking measures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DO-13 |
| CIDR Block | 146.190.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-29 10:33:27 UTC |
| Last Seen | 2026-08-12 23:15:51 UTC |
| Profile Built | 2026-08-12 23:18:09 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 20 |
Full dossier details are available via our API.