# IP Intelligence Briefing: 138.197.107.163
## Executive Summary
IP address 138.197.107.163 operates on DigitalOcean cloud infrastructure in the United States with a low-risk classification (Risk Score: 25/100). The IP exhibits standard web hosting characteristics with no active threat indicators, though it is listed on one DNSBL and shows geolocation validation anomalies requiring monitoring.
## Infrastructure Profile
- Organization: DigitalOcean, LLC (ASN 14061)
- Location: Clifton, NJ, US
- Infrastructure Type: Cloud Compute / Web Hosting
- Network Role: Web Server
- BGP Prefix: 138.197.96.0/20
## Service Exposure
| Port | Protocol | Service |
|---|---|---|
| 80 | TCP | HTTP |
| 443 | TCP | HTTPS |
| 22 | TCP | SSH |
- Server Fingerprint: Caddy web server
- TLS Certificate: None detected
- Reverse DNS: Not resolved
## Threat Assessment
- Overall Risk Score: 25 (Low Risk)
- Abuse Confidence: Not applicable
- Known Campaigns: None detected
- Blacklist Status: Listed on 1 of 8 DNSBLs
- Tor/Proxy/VPN: Not identified
- Persistently Malicious: No
## Neighborhood Analysis
- Subnet: 138.197.107.163/24
- Abuse Density: 0%
- Subnet Classification: Clean
- Threat Siblings: 0
- Inherited Risk: 0
## Relationship Mapping
All 27 detected relationships identify the same DIGITALOCEAN-138-197-0-0 network block, indicating consistent cloud infrastructure placement with no suspicious external entity associations.
## Historical Observations (19 Total)
- Most Recent Signal: 2026-06-26T16:15 - HTTPS connection failure
- Operator Score: 0 (Minimal)
- Route Stability: Unstable (0 route changes in 30-day window)
- Observation Trend: Consistent low-risk classification; no escalation detected
## Geolocation Validation
- Geo Plausibility: False
- Distance: 5967.6 km
- Min RTT: 22ms
- Minimum Possible RTT: 119.4ms
- Status: RTT violation detected (22.0ms < 119.4ms threshold)
## Recommended Actions
1. Monitor: Track DNSBL listing persistence; investigate single-list status
2. Verify: Confirm geolocation discrepancy against known DigitalOcean facility locations
3. Baseline: Establish operational baseline for cloud compute infrastructure
4. No Blocking: Current risk profile does not warrant immediate blocking
## Conclusion
138.197.107.163 represents a standard DigitalOcean cloud hosting endpoint with minimal threat characteristics. The single DNSBL listing and geolocation validation anomaly warrant routine monitoring but do not indicate active malicious activity. Standard cloud infrastructure controls apply.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Caddy |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 28% | 2 | 3 |
| ownership | 17% | 2 | 3 |
| reputation | 27% | 1 | 3 |
| geolocation | 37% | 2 | 3 |
| Overall | 25% | 10 | 17 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-12 09:40:07 UTC |
| Last Seen | 2026-06-27 21:09:04 UTC |
| Profile Built | 2026-06-28 15:14:14 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 25 |
Full dossier details are available via our API.