# IP INTELLIGENCE BRIEFING
Target: 46.101.107.202/32
Classification: Moderate Risk (Risk Score: 50)
Report Date: Current
---
## EXECUTIVE SUMMARY
The IP address 46.101.107.202 is a DigitalOcean cloud infrastructure asset located in Frankfurt am Main, Germany (DE). The asset is classified as moderate risk (score 50) and is associated with domain nwasel.net. Recent DNSBL listings indicate potential abuse activity requiring monitoring. The /24 subnet demonstrates clean classification with zero abuse density, suggesting isolated rather than coordinated malicious activity.
---
## NETWORK ATTRIBUTES
| Attribute | Value |
|---|---|
| ASN | 14061 (DigitalOcean) |
| Organization | digitalocean |
| RIR | RIPE |
| Geolocation | Frankfurt am Main, DE |
| Infrastructure Type | Cloud/Web Server |
| DNSBL Status | 2/8 lists listed |
| Operator Score | 0.3478 (Basic) |
---
## THREAT INDICATORS
- Risk Classification: Moderate Risk (Score: 50)
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Open Ports: 22 (SSH), 443 (HTTPS)
- TLS Certificate: Let's Encrypt (CN=nwasel.net)
- Historical Observations: 58 signals
- Threat Persistence: Single observation period (not persistently malicious)
Recent history indicates DNSBL listings with maximum severity rated as "high" on multiple threat feeds. Route stability remains consistent with no observed BGP changes in the last 30 days.
---
## RELATIONSHIP ANALYSIS
- Total Relationships: 171
- Network Association: Multiple DIGITALOCEAN network relationships confirmed
- Related Entities: No associated hostnames, organizations, or certificates beyond network-level associations
- Campaign Correlation: None detected
---
## NEIGHBORHOOD ASSESSMENT
Subnet: 46.101.107.202/24
Abuse Density: 0
Classification: Clean
Threat Siblings: 0
Active Siblings: 1
The /24 subnet exhibits no inherited risk from neighboring addresses. This supports assessment of the IP as an isolated incident rather than part of a larger malicious infrastructure cluster.
---
## RECOMMENDED ACTIONS
Based on IPDebrief risk profile, the following firewall rules are recommended:
```bash
# iptables
iptables -A INPUT -s 46.101.107.202 -j DROP
# nftables
nft add rule inet filter input ip saddr 46.101.107.202 drop
# nginx
deny 46.101.107.202;
# Cloudflare WAF
ip.src eq 46.101.107.202
# AWS WAF
Addresses: 46.101.107.202/32
```
Note: These recommendations are probabilistic and should be combined with other threat intelligence signals before implementing blocking actions.
---
## INTELLIGENCE NOTES
1. Domain Association: The IP resolves to nwasel.net with valid Let's Encrypt TLS certificate.
2. Geographic Origin: Frankfurt, DE (Europe/Berlin timezone)
3. Risk Trend: Single threat observation detected; no persistent malicious activity pattern observed
4. Infrastructure: Cloud-hosted environment on DigitalOcean platform
5. Action Priority: Monitor for additional activity; block if legitimate traffic patterns do not match expected profile
---
End of Briefing
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | digitalocean |
| ASN | AS14061 |
| Network Name | โ |
| CIDR Block | 46.101.96.0/19 |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 22 | ssh | tcp | โ |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 4 |
| routing | 20% | 2 | 3 |
| services | 28% | 2 | 3 |
| ownership | 33% | 3 | 7 |
| reputation | 24% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 28% | 12 | 23 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:22 UTC |
| Last Seen | 2026-06-27 05:39:39 UTC |
| Profile Built | 2026-06-27 23:45:24 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 44 |
Full dossier details are available via our API.