IP Intelligence Briefing: 138.197.93.235
*Generated via IPDebrief tools: Profile, History, Relationships, & Neighborhood Analysis*
---
**1. IP Profile**
- Risk Score: Moderate (50/100)
- Ownership: DigitalOcean, LLC (ASN 14061, CIDR 138.197.0.0/16)
- Geolocation: New Jersey, US (plausible, 2500km accuracy radius)
- Network Role: CloudCompute (DigitalOcean cloud instance)
- Threat Indicators: No malicious activity detected; no known attacker, spam, or Tor associations.
---
**2. Observation History**
- Recent Activity:
- No persistent malicious behavior (threat persistence days = 0).
- DNSBL listings: 2 out of 8 total lists (low-severity).
- Geolocation consistency: Plausible (US, New Jersey).
- Stability: Stable network route (no recent route changes).
---
**3. Relationships**
- Linked Entities:
- Subnet: `DIGITALOCEAN-138-197-0-0` (138.197.0.0/16).
- No direct links to domains, certificates, or organizations beyond DigitalOcean.
---
**4. Neighborhood Analysis**
- Subnet: 138.197.93.235/24
- Abuse Density: 0% (mostly clean).
- Neighbors:
- 138.197.93.245: Risk score 25 (low risk, moderate authority score).
- No other high-risk neighbors.
---
**5. Recommendations**
- Monitor: Track 138.197.93.245 for potential lateral movement or increased risk.
- Access Control: Ensure cloud instance (DigitalOcean) has strict IAM/Network ACLs.
- DNS: Verify DNSSEC and CAA records for subdomains (no SPF/DMArc detected).
- Threat Feeds: Cross-check with DNSBLs for any emerging threats.
---
Conclusion:
This IP is a legitimate DigitalOcean cloud instance with no immediate malicious indicators. While the subnet is mostly clean, the neighbor 138.197.93.245 shows moderate risk. SOC teams should maintain standard cloud security practices and monitor for anomalies.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-138-197-0-0 |
| CIDR Block | 138.197.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| 8080 | http-alt | tcp | β |
| Closed Ports | 25, 3389, 8443 (4 open / 7 scanned) | ||
| Server | nginx/1.27.5 |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | catalystcivic.orgwww.catalystcivic.org |
| Valid From | 2026-06-14T22:47:23+00:00 |
| Valid Until | 2026-09-12T22:47:22+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 05C7C9CB4B66CA481ED873AE505F9E3DD118 |
| Thumbprint | B1D783C02FB96F73C8C52847F70B013404C4E927 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 35% | 2 | 3 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 17% | 1 | 1 |
| Overall | 26% | 9 | 13 |
| Data Coherence | Mostly Consistent (85%) β 1 contradiction(s) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Fresh
| First Seen | 2026-06-09 14:17:21 UTC |
| Last Seen | 2026-06-26 18:10:36 UTC |
| Profile Built | 2026-06-26 21:31:13 UTC |
| Data Freshness | Fresh |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.