IP Intelligence Briefing: 157.245.219.150
Date: 2026-06-11
---
**1. Core Profile**
- Risk Score: 50 (Moderate Risk)
- Provider: DigitalOcean, LLC (ASN 14061)
- Geolocation: United States (New Jersey), inferred with 65% confidence (latitude 39.83, longitude -98.58).
- Network Role: Cloud compute instance (DigitalOcean infrastructure).
- Threat Indicators: No malicious activity detected (no indicators, blacklists, or campaigns).
---
**2. Observation History**
- Latest Geolocation: Inferred as US (New Jersey) with 65% confidence.
- DNSBL Listings: 1 out of 8 lists (confidence 85%), but no specific lists identified.
- Operator Score: Minimal risk (0.13), indicating stable, legitimate provider.
- Temporal Trends: No persistent malicious activity; threat observation count: 1.
---
**3. Relationships & Network**
- Network Affiliation: Part of the `DIGITALOCEAN-157-245-0-0` network (ASN 14061).
- Subnet Neighbors: No active or malicious sibling IPs in the 157.245.219.0/24 subnet.
- Connections: No direct links to hostnames, organizations, or certificates.
---
**4. Mitigation Recommendations**
- Firewall Rules:
- iptables: `iptables -A INPUT -s 157.245.219.150 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 157.245.219.150 drop`
- Cloudflare/WAF: Block IP with rule `{ "action": "block", "expression": "ip.src eq 157.245.219.150" }`
- Action Notes: No immediate action required due to low risk. Monitor for unusual behavior.
---
**5. Summary**
The IP is a legitimate DigitalOcean cloud instance with no evidence of malicious activity. While geolocation and DNSBL data suggest plausible but unconfirmed risks, the overall profile indicates a low to moderate risk. SOC teams should monitor it as part of standard procedures but do not need to block it unless additional context emerges.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-157-245-0-0 |
| CIDR Block | 157.245.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.31.1 |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | staging.svcboard.com |
| Valid From | 2026-05-29T19:25:11+00:00 |
| Valid Until | 2026-08-27T19:25:10+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 0538CA315D18E7F9868542F6416667CB66DC |
| Thumbprint | E4DC76E2A22D5DFD934B6C235E72898481B3B4CE |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 40% | 2 | 3 |
| Overall | 27% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-26 06:50:13 UTC |
| Last Seen | 2026-06-29 02:44:03 UTC |
| Profile Built | 2026-06-29 08:45:58 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.