# IP Intelligence Briefing: 157.245.148.118
Date: 2026-08-13
Classification: Moderate Risk (50/100)
Assigned: IPDebrief Intelligence Team
---
## 1. Executive Summary
IP address 157.245.148.118 is a DigitalOcean cloud compute instance assigned to the DIGITALOCEAN-157-245-0-0 network block (157.245.0.0/16). The IP carries a moderate risk score of 50 with evidence of blacklist presence (2 of 8 DNSBL sources, high severity). No active services were detected on the IP, and no threat indicators were flagged in the profile.
---
## 2. Ownership and Infrastructure
| Attribute | Value |
|---|---|
| ASN | 14061 |
| Organization | DigitalOcean, LLC |
| CIDR Block | 157.245.0.0/16 |
| RIR | ARIN |
| Infrastructure Type | Cloud Compute |
| Host Status | Hosting |
The IP is confirmed to be part of a cloud hosting environment with no evidence of proxy, CDN, or VPN infrastructure.
---
## 3. Geolocation Analysis
- Primary Location: Singapore (SG)
- Coordinates: 1.314°N, 103.6839°E
- Geo-Validation: Validated (geoplausible = true)
- Control Plane: BGP prefix 157.245.144.0/20
Multiple geolocation sources were queried. One observation returned US coordinates (39.83°N, -98.58°W) with low confidence (0.35), indicating potential geolocation spoofing or database inconsistency.
---
## 4. Threat Intelligence Indicators
| Indicator | Status |
|---|---|
| DNSBL Listings | 2 of 8 lists (high severity) |
| Known Attacker | No |
| Tor Exit Node | No |
| Spam Source | No |
| Open Ports | None detected |
| TLS Certificate | None |
| Hosted Domains | None |
DNSSEC validation confirmed for the reverse DNS zone (118.148.245.157.in-addr.arpa).
---
## 5. Neighborhood Assessment
- Subnet: 157.245.148.118/24
- Abuse Density: 0
- Neighbor Count: 1
- Neighbor IP: 157.245.148.140 (Risk: 25, Authority: 50)
The /24 subnet shows minimal abuse activity. The sole neighbor IP carries a lower risk profile (25) and higher authority score (50), suggesting it is likely a legitimate cloud host.
---
## 6. Observation History
13 observations recorded. Key signals:
- Geolocation: Singapore (confidence 0.70)
- DNSSEC: Validated (confidence 0.90)
- Blacklist Status: Listed on 8 sources with 2 active high-severity listings (confidence 0.85)
- Network Validation: ICMP validation failed due to blocking (violation noted)
---
## 7. Recommended Actions
The system recommends blocking this IP. Below are the recommended firewall rules:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 157.245.148.118 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 157.245.148.118 drop` |
| Nginx | `deny 157.245.148.118;` |
| pfSense | `157.245.148.118/32` |
| Cloudflare WAF | Block IP β IPDebrief risk score 50 |
| AWS WAF | Address: 157.245.148.118/32 |
---
## 8. Analyst Notes
- The moderate risk score (50) is primarily driven by DNSBL listings rather than active exploit attempts or known attack campaigns.
- No correlation to known threat campaigns or banner matches.
- The absence of open ports and services suggests the IP may have been recently provisioned or is currently dormant.
- Cross-reference with internal telemetry to determine if outbound connections from this IP have been observed.
End of Briefing
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-157-245-0-0 |
| CIDR Block | 157.245.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 37% | 2 | 6 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 43% | 1 | 19 |
| geolocation | 27% | 2 | 3 |
| Overall | 28% | 10 | 34 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-11 17:58:08 UTC |
| Last Seen | 2026-09-11 15:49:08 UTC |
| Profile Built | 2026-09-11 09:47:50 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 61 |
Full dossier details are available via our API.