IP Intelligence Briefing: 139.59.220.152
Date: 2026-06-13
---
**1. IP Profile**
- Risk Score: 25 (Low Risk)
- Provider: DigitalOcean (ASN 14061)
- Geolocation: Singapore (SG), Latitude 1.35, Longitude 103.82
- Network Role: CloudCompute (DigitalOcean Hosting)
- Threat Indicators: No malicious activity detected (no indicators, blacklists, or campaigns).
- DNS: No public PTR records or domain associations.
- Services: No open ports or TLS certificates identified.
- Control Plane: BGP prefix `139.59.220.0/22` managed by DigitalOcean.
---
**2. Observation History**
- Recent Activity (Last 30 Days):
- Minimal risk signals (confidence: 0.2β0.3).
- No spikes in threat indicators or DNS anomalies.
- Stable geolocation and network ownership (DigitalOcean).
- Temporal Trends: No persistent malicious behavior or ownership changes.
---
**3. Relationships**
- Linked Entities:
- Multiple "Same Network" relationships to `DIGITALOCEAN-AP` (subnetwork).
- No associations with hostnames, organizations, or certificates.
- Network Context: Isolated within its /24 subnet; no peer relationships.
---
**4. Neighborhood Analysis**
- Subnet: `139.59.220.152/24`
- Abuse Density: 0% (clean subnet).
- Neighbors: 0 active IPs in the subnet; no risky siblings.
---
**5. Actionable Insights**
- SOC Recommendation:
- Monitor for unexpected service changes or DNS activity, given the cloud-hosted nature.
- No immediate mitigation required due to low risk profile.
- Verify if the IP is part of a legitimate DigitalOcean instance (e.g., droplet or Kubernetes node).
- Threat Context: No correlation with known malicious campaigns or infrastructure.
---
Conclusion: 139.59.220.152 is a low-risk, cloud-hosted IP under DigitalOcean with no malicious indicators. No action is required unless unusual activity is detected.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Digital Ocean Inc administrator |
| ASN | AS14061 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 28% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 27% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 23% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:40 UTC |
| Last Seen | 2026-06-26 22:33:56 UTC |
| Profile Built | 2026-06-27 18:48:43 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 26 |
Full dossier details are available via our API.