# IP Intelligence Briefing: 137.184.13.100/32
Classification: LOW RISK / MONITOR
Date: 2026-08-05
Analyst: IPDebrief Intelligence System
---
## Executive Summary
IP address 137.184.13.100 is registered to DigitalOcean, LLC and presents a low-risk profile (risk score: 25). The IP is classified as cloud infrastructure with minimal threat indicators. No actionable firewall recommendations were generated, though routine monitoring is advised due to observed DNS associations with third-party scanning infrastructure.
---
## Ownership and Infrastructure
| Attribute | Value |
|---|---|
| **ASN** | 14061 (DigitalOcean, LLC) |
| **Organization** | DIGITALOCEAN-137-184-0-0/16 |
| **Location** | Santa Clara, California, US |
| **Infrastructure Type** | Cloud Compute |
| **Classification** | Cloud Hosting |
The IP resides within DigitalOcean's cloud compute network. The subnet (137.184.0.0/16) is well-established with no ownership changes detected.
---
## Network Role and Services
Open Services:
- Port 22/TCP (SSH) - SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16
DNS Resolution:
- PTR Record: `gravy.scanf.shodan.io`
- Forward Resolution: Confirmed
- Hosted Domains: None
Control Plane:
- Route stability: Unstable
- DNSBL Listed: 1 of 8 total lists
- Operator Score: 0.2609 (Basic)
---
## Threat Assessment
Risk Indicators:
- Overall Risk Score: 25 (Low Risk)
- Abuse Confidence: Not applicable
- Blacklist Count: 0
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Threat Feeds: None active
---
## Observation History
Temporal Analysis:
- Observations: 20 signals tracked
- Latest: 2026-08-05T16:14:16 UTC
- Threat Persistence: 0 days (not persistently malicious)
Recent Signals:
1. 2026-08-05: 8 total blacklist listings, 1 listed (max severity: High)
2. 2026-08-05: Operator score assessment (Basic, 0.2609)
3. 2026-07-29: RTT validation anomalies detected
4. 2026-07-29: Campaign likelihood: None
Geolocation Validity:
- Status: Inconsistent
- Claimed Location: Santa Clara, California (37.3931, -121.962)
- RTT Violation: 83ms observed vs 177.2ms minimum possible for 8,857.7km distance
- Probes: 5
- GeoPlausible: False
---
## Relationship Graph
Identified Associations:
- DNS: gravy.scanf.shodan.io (repeated associations)
- Network: DIGITALOCEAN-137-184-0-0 (same network)
- Organization: DigitalOcean, LLC
- Certificates: None
Analysis: The repeated DNS association with `gravy.scanf.shodan.io` indicates this IP is being probed by shodan.io scanning infrastructure. This is common behavior for cloud infrastructure.
---
## Neighborhood Assessment
Subnet Analysis: 137.184.13.0/24
- Abuse Density: 0 (Clean)
- Classification: Clean
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 0
- Risk Distribution: 0 High, 0 Medium, 0 Low
The immediate /24 neighborhood shows no abuse or threat activity, suggesting this IP exists in a low-abuse cloud subnet.
---
## Recommended Actions
Risk Score: 25 (Low)
No immediate blocking actions recommended. However, the following considerations apply:
1. Monitor DNS associations with shodan.io scanning infrastructure
2. Validate geolocation consistency due to RTT violations
3. Review SSH exposure on port 222
Firewall Rules: None generated (low-risk profile)
---
## Intelligence Conclusion
IP 137.184.13.100 represents standard cloud infrastructure with minimal threat posture. The single blacklist listing and DNS association with scanning infrastructure warrant routine monitoring but do not indicate malicious activity. The geolocation inconsistency is noted as a data quality issue rather than a threat indicator.
Priority: LOW
Action: Monitor
Next Review: Standard periodic review
---
*Generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-137-184-0-0 |
| CIDR Block | 137.184.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | gravy.scanf.shodan.io |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | gravy.scanf.shodan.io |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 32% | 2 | 3 |
| Overall | 23% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-21 19:02:45 UTC |
| Last Seen | 2026-08-12 16:08:35 UTC |
| Profile Built | 2026-08-12 16:21:25 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.