# IP Intelligence Briefing: 138.197.171.56/32
## Executive Summary
The IP address 138.197.171.56 is a DigitalOcean cloud infrastructure endpoint located in Toronto, Ontario, Canada (AS14061). The IP carries a moderate risk score of 40 and demonstrates concerning behavioral indicators including DNS blacklist listings and proxy detection signals. Despite showing no active open services, the IP exhibits route instability and historical proxy associations warranting defensive attention.
---
## Profile Assessment
Ownership & Infrastructure:
- Provider: DigitalOcean, LLC (AS14061)
- Network: DIGITALOCEAN-138-197-0.0/16
- Geolocation: Toronto, Ontario, Canada (CA)
- Classification: CloudCompute infrastructure, not CDN/VPN/proxy/Tor
- Status: Firewalled with no services detected
Risk Metrics:
- Overall Risk Score: 40 (Moderate)
- DNS Blacklist Presence: Listed on 2 of 8 total DNS blocklists
- Route Stability: Flagged as unstable (isRouteStable: false)
- Geo Validation: Inconsistencies detected (geoPlausible: false)
- Control Plane: BGP prefix 138.197.160.0/20
DNS Intelligence:
- PTR Hostname: prod-bromine-tor1-4.do.binaryedge.ninja
- Reverse Resolution: Confirmed to binaryedge.ninja domain
- Email Authentication: SPF enabled, DMARC absent
- Forward Resolution: Single hostname association
Threat Indicators:
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Abuse Confidence Score: Not available
- Campaign Associations: None identified
- Threat Feeds: Empty
---
## Observation History Analysis
The IP has generated 18 signal observations. Key findings from recent observations include:
- Proxy Detection Signal (Aug 2026): Signal from proxycheck-io flagged the IP as a "Compromised Server" with proxy type classification and risk score of 83.
- DNS Blacklist Activity: Multiple listings detected with "high" severity categorization across multiple blacklist sources.
- Ownership Stability: No ownership changes recorded; average ownership duration indicates stable hosting.
- Threat Persistence: Zero threat persistence days; not classified as persistently malicious.
The history indicates episodic threat activity rather than sustained malicious operation.
---
## Network Relationships
Seven relationship entities were identified:
- Same Network: DIGITALOCEAN-138-197-0.0 (multiple associations)
- DNS Associations: prod-bromine-tor1-4.do.binaryedge.ninja hostname
- Correlated Entities: Limited to network and DNS-level relationships only
No organization, certificate, or hostname relationships beyond the immediate DNS resolution were discovered.
---
## Subnet Neighborhood Assessment
Subnet: 138.197.171.56/24
- Total Sibling IPs: 1 active sibling identified (138.197.171.83)
- Abuse Density: 0
- Risk Distribution: 1 low-risk sibling
- Sibling IP Profile: 138.197.171.83 carries risk score 25 and authority score 50
The subnet demonstrates low abuse density, suggesting isolated rather than coordinated malicious activity.
---
## Recommended Security Actions
Based on the risk profile (40), the following defensive measures are recommended:
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 138.197.171.56 -j DROP
# nftables
nft add rule inet filter input ip saddr 138.197.171.56 drop
# nginx
deny 138.197.171.56;
```
WAF Implementation:
- Cloudflare WAF: Block with expression `ip.src eq 138.197.171.56`
- AWS WAF: Add to block list for 138.197.171.56/32
Recommended Action: BLOCK this IP at network perimeter and application layer. The combination of DNS blacklist presence, proxy detection signals, and route instability supports this recommendation, though defensive teams should correlate with internal telemetry before enforcement.
---
## Intelligence Conclusions
138.197.171.56 presents a moderate threat profile with documented blacklist presence and proxy detection signals. The absence of open services and low neighborhood abuse density suggests either dormant infrastructure or evasive operational techniques. The IP should be blocked at defensive boundaries pending further correlation with internal security telemetry. Continued monitoring recommended for related IP 138.197.171.83 within the same subnet.
---
*Generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-138-197-0-0 |
| CIDR Block | 138.197.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | prod-bromine-tor1-4.do.binaryedge.ninja |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | prod-bromine-tor1-4.do.binaryedge.ninja |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 17% | 1 | 1 |
| Overall | 24% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-01 04:25:00 UTC |
| Last Seen | 2026-08-13 02:18:19 UTC |
| Profile Built | 2026-08-13 02:25:10 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.