IP Intelligence Briefing: 146.190.63.48
*Generated via IPDebrief Threat Intelligence Platform*
---
**1. Risk Profile**
- Risk Score: 50 (Moderate Risk)
- Provider: DigitalOcean, LLC (ASN 14061)
- Geolocation: Santa Clara, CA, US (geo-plausibility flagged due to RTT inconsistency)
- Network Role: CloudCompute (DigitalOcean infrastructure)
- Threat Indicators: No malicious activity detected; no known campaigns, spam, or blacklist associations.
---
**2. Observation History**
- Latest Observation: June 9, 2026 (HTTP/1.1, lighttpd/1.4.59 server)
- Geolocation Validation:
- RTT Anomaly: 86ms observed vs. expected 177ms for 8858km distance.
- Accuracy: 2500km radius (low precision).
- Stability: Route stability flagged as "unstable" (BGP route changes detected).
---
**3. Relationships & Associations**
- Network Links:
- Same network: `DO-13` (DigitalOcean subnet).
- DNS: `cdac169393.scan.leakix.org` (associated with a scan tool).
- Certificates & Services:
- No TLS certificates detected.
- Open ports: HTTP (80), SSH (22).
- SSH banner: `SSH-2.0-OpenSSH_8.4p1`.
---
**4. Neighborhood Analysis**
- Subnet: `146.190.63.48/24`
- Abuse Density: 0.5 (low risk).
- Neighbors:
- `146.190.63.248` (risk score: 25, authority score: 60).
- Inherited Risk: 2 (moderate).
---
**5. Actionable Insights**
- Monitor Geolocation Discrepancy: Investigate RTT anomaly; potential spoofing or misconfigured routing.
- Verify DNS Associations: Scrutinize `cdac169393.scan.leakix.org` for scan tool activity.
- Check SSH Access: Ensure SSH keys are secured, given the OpenSSH version.
- No Immediate Mitigation Required: Low abuse density and no active threats.
---
*End of Briefing*
*Generated by IPDebrief | © 2026 Jason Alberino*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | cdac169393.scan.leakix.org |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | cdac169393.scan.leakix.org |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | lighttpd/1.4.59 |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.4p1 Debian-5+deb11u7 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 46% | 2 | 8 |
| routing | 13% | 1 | 1 |
| services | 28% | 2 | 4 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 28% | 10 | 22 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:44 UTC |
| Last Seen | 2026-06-26 23:31:57 UTC |
| Profile Built | 2026-06-27 19:45:25 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 36 |
Full dossier details are available via our API.