IP Intelligence Briefing: 139.59.58.25
Date: 2026-06-12
---
**1. Core Profile**
- Risk Score: 40 (Moderate Risk)
- Provider: DigitalOcean (ASN 14061)
- Geolocation: India (Karnataka, Bengaluru)
- Network Role: Cloud Compute (Hosting, Web Server)
- Threat Indicators: No direct malicious activity detected (no malware, C2, or exploit signs).
---
**2. Threat Observations**
- DNSBL Listings (3/8):
- High-severity entries detected (e.g., *zombie.email*, *spamhaus*).
- *goldionaire.com* linked via DNS records (SPF/DKIM configured).
- TLS/HTTP:
- Valid Letโs Encrypt certificate (SAN: goldionaire.com).
- HTTP/2 over Nginx, no HSTS or CSP headers.
- Open Ports:
- 80 (HTTP), 443 (HTTPS), 22 (SSH), 8443 (HTTPS-alt).
---
**3. Network Relationships**
- Subnet: 139.59.58.25/24 (DigitalOcean CIDR: 139.59.56.0/21).
- Neighbors:
- 139.59.58.173 (risk score: 50, moderate risk).
- BGP:
- Route stability: Unstable (0 route changes in 30 days).
- RPKI invalid: No state reported.
---
**4. Historical Trends**
- Recent Activity (June 2026):
- DNSBL listings increased to 3 (from 0 in prior months).
- TLS certificate renewed; no revoked certificates detected.
- No persistent malicious behavior (0 threat persistence days).
---
**5. Recommendations**
- Monitor DNSBL Entries: Investigate *goldionaire.com* for spam or phishing activity.
- Validate TLS: Ensure certificate validity and SAN alignment with legitimate domains.
- Network Segmentation: Isolate high-risk neighbors (e.g., 139.59.58.173) if shared subnet access is required.
- Log Analysis: Check SSH access logs for unauthorized activity on port 22.
---
Conclusion:
This IP is a legitimate DigitalOcean cloud instance with no direct malicious indicators. However, its association with DNSBL listings and potential subnetwork risks warrants closer monitoring. SOC teams should prioritize validating linked domains and ensuring network segmentation to mitigate lateral movement risks.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Digital Ocean Inc administrator |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-AP |
| CIDR Block | 139.59.56.0/21 |
| RIR | ARIN |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| 8443 | https-alt | tcp | โ |
| Closed Ports | 25, 3389, 8080 (4 open / 7 scanned) | ||
| Server | nginx |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.15 |
๐ TLS Certificate
CN=goldionaire.com was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.| SANs | goldionaire.comwww.goldionaire.com |
| Valid From | 2026-03-23T18:08:12+00:00 |
| Valid Until | 2026-06-21T18:08:11+00:00 (expired) |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 056C24A3F8F62178EF75039EADFE9DAF8957 |
| Thumbprint | 644288E0E882FB7DB09DC1C217018E330BA0832C |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 34% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 25% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-30 10:57:56 UTC |
| Last Seen | 2026-06-29 07:28:05 UTC |
| Profile Built | 2026-06-29 13:30:51 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.