IPDebrief

157.245.125.199

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

## IP Intelligence Briefing: 157.245.125.199/32

Classification: Low Risk – Cloud Infrastructure Web Server

Report Date: 2026-06-21

---

Executive Summary

IP address 157.245.125.199 is a DigitalOcean cloud-hosted web server with an overall risk score of 25 (Low Risk). The IP exhibits no active threat indicators and maintains a "mostly_clean" classification within its /24 subnet. While geolocation data shows inconsistencies and the subnet contains two threat-adjacent neighbors, the IP itself shows no persistent malicious behavior. No immediate defensive action required.

---

Technical Profile

Ownership & Infrastructure

Network Services

---

Threat Assessment

Risk Metrics

Control Plane Analysis

---

Neighborhood Context

Subnet: 157.245.125.0/24

Notable Neighbor:

---

Observation History

---

Anomalies & Concerns

1. Geolocation Inconsistency: geoPlausible flag is false. Probe data indicates RTT of 25.0ms, which is significantly below the minimum possible 119.4ms for a 5,968km distance, suggesting unreliable geolocation reporting.

2. Route Stability: BGP routing shows instability (isRouteStable: false), which may indicate transient traffic patterns or infrastructure changes.

3. DNSBL Presence: 1 DNSBL listing detected across 8 total lists. Further investigation of blacklist specifics may be warranted.

---

Recommended Actions

Current Risk Level: LOW

Monitoring Recommendations:

For SOC Analysts:

This IP represents legitimate cloud infrastructure with low observed risk. No immediate incident response or blocking required. If this IP appears in incident logs, investigate context (legitimate traffic vs. compromised host). The domain production.unitingurantia.org should be verified as expected legitimate traffic.

---

Related Entities

0/24 subnet)

---

Final Assessment

The IP address 157.245.125.199 represents a standard cloud web hosting environment with minimal observed threat activity. The risk profile is consistent with legitimate DigitalOcean infrastructure. The primary concern remains the geolocation data inconsistency and the presence of threat-adjacent neighbors in the immediate /24 subnet, neither of which indicate direct compromise of this specific IP.

Threat Level: LOW

Action Required: None

Review Interval: Periodic monitoring recommended if traffic anomalies emerge

---

End of Intelligence Briefing

Generated by IPDebrief

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionNJ
CityClifton
Timezoneβ€”
Latitude40.84
Longitude-74.14

🏒 Ownership & Registration

OrganizationDigitalOcean, LLC
ASNAS14061
Network NameDIGITALOCEAN-157-245-0-0
CIDR Block157.245.0.0/16
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score60% (Good)
SPF2/2 domains
DMARC1/2 domains
FCrDNSNot verified
DNSSECValid
CAANot configured
Domains Checked2 domains

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
Closed Ports22, 25, 3389, 8080, 8443 (2 open / 7 scanned)
Servernginx/1.14.0 (Ubuntu)
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
CN=production.unitingurantia.org
Issued by CN=R12, O=Let's Encrypt, C=US
Self-signed: No
SANsproduction.unitingurantia.orgstaging.unitingurantia.org
Valid From2026-05-18T18:35:01+00:00
Valid Until2026-08-16T18:35:00+00:00
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
Signature Algorithmsha256RSA
Validity Period89 days
Serial Number067FF8FB9894D5D2EBB7D81569EE734CA7D7
ThumbprintCC65AAB035096C39C8D52B14AC99963140A35E29

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
24
routing
13%
11
services
27%
23
ownership
27%
23
reputation
22%
13
geolocation
33%
24
Overall25%1018
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-30 10:58:11 UTC
Last Seen2026-06-29 07:31:12 UTC
Profile Built2026-06-29 07:34:34 UTC
Data FreshnessLive
Signal Types23
Total Observations24
πŸ” 23 signal types Β· 24 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.