IP Intelligence Briefing: 138.197.97.170
Date: June 7, 2026
1. Profile Summary
- Risk Score: Moderate (50/100)
- Ownership: DigitalOcean, LLC (ASN 14061)
- Geolocation: Clifton, NJ, USA (geo-plausibility: false)
- Network Role: CloudCompute (nginx/1.24.0 server, SSH, HTTP/HTTPS services)
- Threat Indicators: No malicious activity detected (no abuse confidence, blacklist, or campaign ties).
2. Observation History
- Recent Activity:
- HTTP/HTTPS services observed on ports 80, 443, and SSH (port 22).
- TLS certificate: Valid Letβs Encrypt certificate for `lucaspetshop.duckdns.org`.
- DNSSEC validation successful; no DNSBL listings.
- Temporal Trends: Stable over 30 days (no persistent malicious patterns).
3. Relationships
- Network Links:
- Subnet: `138.197.97.170/24` (abuse density: 1, classification: "mostly_clean").
- Linked to DigitalOceanβs `DIGITALOCEAN-138-197-0-0` network.
- DNS Associations:
- Multiple DNS resolution errors (timed out) for internal IP `192.168.2.108`.
4. Neighborhood Analysis
- Subnet: `138.197.97.170/24`
- Neighbors: No active sibling IPs detected (0 neighbors).
- Abuse Density: Low (0/24 IPs flagged).
5. Recommendations
- Monitor DNS Configuration: Investigate recurring DNS timeout errors (may indicate misconfigured resolvers or network segmentation).
- Validate Server Security: Ensure nginx and SSH configurations align with DigitalOceanβs security best practices.
- Continuous Monitoring: Track TLS certificate renewals and HTTP service behavior for anomalies.
Conclusion:
This IP is associated with a legitimate DigitalOcean cloud server, showing no signs of malicious activity. Focus on resolving DNS resolution issues and maintaining server compliance. No immediate mitigation required, but ongoing monitoring is advised.
Tools Used: `ipdebrief_profile`, `ipdebrief_history`, `ipdebrief_relationships`, `ipdebrief_neighbors`.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | lucaspetshop.duckdns.org |
| Valid From | 2026-05-17T05:43:52+00:00 |
| Valid Until | 2026-08-15T05:43:51+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 050A888D30C494C364AE38EA5817AB55B8E6 |
| Thumbprint | 80E62248B8344324DF838BFCB27E29DF6432660F |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 25% | 2 | 4 |
| ownership | 17% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 18 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-14 19:27:58 UTC |
| Last Seen | 2026-06-28 01:11:39 UTC |
| Profile Built | 2026-06-28 19:16:22 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 27 |
Full dossier details are available via our API.