## IP INTELLIGENCE BRIEFING: 207.154.222.104/32
Classification: HIGH RISK โ Cloud Infrastructure
Date: August 2026
Analyst: IPDebrief Intelligence Team
---
Executive Summary
IP address 207.154.222.104 is classified as HIGH RISK (Score: 80/100) and is associated with DigitalOcean cloud infrastructure. While the source network (207.154.222.0/24) shows clean abuse density metrics, this specific IP has been flagged by 4 DNSBLs and exhibits elevated risk characteristics warranting defensive monitoring.
---
Ownership & Infrastructure
| Attribute | Value |
|---|---|
| **Organization** | DigitalOcean, LLC |
| **ASN** | 14061 |
| **Network Block** | 207.154.192.0/18 |
| **Netname** | DIGITALOCEAN-207-154-192-0 |
| **Geolocation** | Frankfurt am Main, DE |
| **Infrastructure Type** | Cloud Compute |
---
Threat Assessment
Risk Score: 80/100 (High Risk)
Key Findings:
- Listed on 4 DNSBL entries out of 8 total lists checked
- No open services detected on ports
- No active threat indicators (no known campaigns, not a Tor exit node)
- No persistent malicious behavior observed in history
- Control plane shows route stability concerns (isRouteStable: false)
Threat Indicators: None detected (empty threat indicators array)
---
Network Context
Subnet Analysis (207.154.222.0/24):
- Abuse Density: 0% (Clean classification)
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 0
Assessment: This IP represents an outlier within its subnet. The subnet itself shows no abuse activity, suggesting the risk is isolated to this single address rather than a compromised network segment.
---
Historical Observation
Total Observations: 17
Recent Activity:
- August 5, 2026: Operator score 0.1304 (Minimal threat)
- July 30, 2026: Network scan detected (ports scanned, no services open)
- Ownership stability: No changes detected
Persistence Analysis: No persistent malicious behavior detected (threatPersistenceDays: 0, isPersistentlyMalicious: false)
---
Relationship Graph
- Same Network: DIGITALOCEAN-207-154-192-0 (5 relationship entries)
- External Relationships: None detected
- Associated Hostnames/Certificates: None
---
Defensive Recommendations
Priority: CRITICAL
Recommended Actions:
1. Increase logging verbosity for traffic from this IP
2. Block at perimeter using provided rulesets
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 207.154.222.104 -j DROP
# nftables
nft add rule inet filter input ip saddr 207.154.222.104 drop
# nginx
deny 207.154.222.104;
```
Cloud/WAF Rules:
- Cloudflare WAF: Block IP 207.154.222.104
- AWS WAF: Add 207.154.222.104/32 to block list
- pfSense: Add 207.154.222.104/32 to block list
---
Analyst Notes
This IP warrants defensive blocking despite the clean subnet environment. The high risk score combined with multiple DNSBL listings indicates prior abuse activity. Monitor for any correlation with known threat actors or campaigns. The isolated nature within the subnet suggests this may be a compromised user instance rather than infrastructure compromise.
Next Review: 7 days post-block implementation
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-207-154-192-0 |
| CIDR Block | 207.154.192.0/18 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 23% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-26 09:12:22 UTC |
| Last Seen | 2026-08-12 20:24:23 UTC |
| Profile Built | 2026-08-12 20:28:29 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 21 |
Full dossier details are available via our API.