IPDebrief

104.236.68.24

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP Intelligence Briefing: 104.236.68.24

Date: 2026-06-16

---

**1. Core Profile**

- Open ports: 80 (HTTP), 443 (HTTPS), 22 (SSH)

- TLS Certificate: Issued by CloudFlare, SANs include `easyserv.com.br`

- Server Banner: `nginx/1.15.8`

---

**2. Threat Indicators**

- DNS records for `robotstxt.org` (SPF validation).

- HTTP headers showing nginx server and potential misconfigurations.

- BGP route stability confirmed (no recent changes).

---

**3. Network Relationships**

---

**4. Risk Assessment**

---

**5. Recommendations**

1. Monitor DNSBL Listings: Investigate why this IP appears on 2 DNSBLs (false positives or misconfigured records).

2. Validate TLS Configuration: Ensure CloudFlare certificates are properly scoped to avoid unintended exposure.

3. Check HTTP Headers: Review nginx server configurations for potential misconfigurations.

4. Subnet Surveillance: Since the subnet has no neighbors, isolate this instance if it hosts sensitive services.

Conclusion: This IP is a legitimate DigitalOcean cloud server with no immediate threats. However, monitor DNSBL listings and TLS configurations for anomalies.

---

*Generated via IPDebrief threat intelligence tools.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionNJ
CityClifton
Timezoneβ€”
Latitude40.84
Longitude-74.14

🏒 Ownership & Registration

OrganizationDigitalOcean, LLC
ASNAS14061
Network NameDIGITALOCEAN-104-236-0-0
CIDR Block104.236.0.0/16
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPF1/2 domains
DMARC0/2 domains
FCrDNSNot verified
DNSSECValid
CAANot configured
Domains Checked2 domains

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierTier 3 β€” Basic operator with some routing infrastructure
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Servernginx/1.15.8
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_6.6.1p1 Ubuntu-2ubuntu2.3

πŸ” TLS Certificate

πŸ”’
CN=CloudFlare Origin Certificate, OU=CloudFlare Origin CA, O="CloudFlare, Inc."
Issued by S=California, L=San Francisco, OU=CloudFlare Origin SSL Certificate Authority, O="CloudFlare, Inc.", C=US
Self-signed: No
SANs*.easyserv.com.breasyserv.com.br
Valid From2025-09-15T19:09:00+00:00
Valid Until2040-09-11T19:09:00+00:00
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period5475 days
Serial Number30E861D9EAC6B413066ACDA48B4DA591FF0F9C07
Thumbprint70BA6DB6D235734277B06623D522016C645FBA6C

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
24
routing
27%
23
services
27%
23
ownership
30%
34
reputation
22%
13
geolocation
24%
23
Overall26%1220
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-28 12:24:32 UTC
Last Seen2026-06-29 05:18:54 UTC
Profile Built2026-06-29 05:24:37 UTC
Data FreshnessLive
Signal Types26
Total Observations27
πŸ” 26 signal types Β· 27 observations collected
This report is generated from 26+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.