# IP Intelligence Briefing: 146.190.41.22/32
## Executive Summary
IP address 146.190.41.22 is classified as Low Risk (Risk Score: 25/100). The endpoint operates as a standard cloud-hosted web server within DigitalOcean's infrastructure with no active malicious indicators detected.
## Technical Profile
- IP Address: 146.190.41.22
- Organization: DigitalOcean, LLC (ASN: 14061)
- Location: Santa Clara, California, United States
- Network Classification: Cloud Compute / Hosting Infrastructure
- Provider Score: 0
- Authority Score: 0
## Network Services & Fingerprinting
- Open Ports: TCP/80 (HTTP), TCP/443 (HTTPS), TCP/22 (SSH)
- Web Server: nginx/1.24.0 (Ubuntu)
- TLS Certificate: Let's Encrypt (CN=liorass.com)
- HTTP Status: 502 (Bad Gateway) observed during fingerprinting
- DNSSEC: Valid
## Threat Assessment
- Abuse Confidence Score: Not applicable
- Blacklist Status: 0 blacklists; 1 DNSBL listing detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Associated Campaigns: None identified
- Operator Label: Minimal (0.1304)
## Temporal Analysis
- Observation History: 20 signals recorded (most recent: 2026-06-15)
- Threat Persistence Days: 0
- Ownership Stability: Stable (0 ownership changes)
- Route Stability: Unstable (isRouteStable: false)
## Neighborhood Context
- Subnet: 146.190.41.0/24
- Subnet Classification: Mostly Clean
- Abuse Density: Low
- Active Siblings: 1
- Threat Siblings: 1 (single sibling flagged)
- Total Siblings: 1
## Relationship Graph
The IP maintains 19 relationships, all classified as "Same Network" (DO-13 DigitalOcean network block). No external entity associations detected beyond network-level relationships.
## Recommended Actions
Based on the risk profile, the following actions are recommended:
Accept:
- Web traffic (HTTP/HTTPS) on ports 80/443
- SSH access on port 22 (verify against internal allowlist)
Monitor:
- 502 error responses may indicate application-level issues or backend service failures
- DNSBL listing requires periodic review
No Action Required:
- No immediate blocking recommended
- No firewall rules necessary for defensive posture
## Intelligence Conclusion
This IP represents legitimate cloud infrastructure hosting a web server. The single DNSBL listing and 502 errors warrant routine monitoring but do not indicate active threat activity. The neighborhood shows minimal threat presence with one sibling flagged, suggesting isolated rather than coordinated activity. Maintain standard cloud hosting security posture.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | liorass.com |
| Valid From | 2026-05-15T07:57:19+00:00 |
| Valid Until | 2026-08-13T07:57:18+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 06D53C017CA70F94CB35C1CD57F563D21EE1 |
| Thumbprint | 06C942BE2B9D167218B4D3AAACFCE95B60E6C137 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 24% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-16 14:57:53 UTC |
| Last Seen | 2026-06-28 03:33:04 UTC |
| Profile Built | 2026-06-28 21:38:39 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.