# IP Intelligence Briefing: 139.59.90.162/32
## Executive Summary
IP address 139.59.90.162 is a DigitalOcean cloud compute infrastructure instance located in the US (New York). The IP maintains a Low Risk reputation profile with a risk score of 25/100. No active threat indicators or malicious activity were detected during the intelligence assessment. The IP is classified as cloud infrastructure with no open services exposed and no established relationships in the relationship graph.
---
## Risk Assessment
- Overall Risk Score: 25 (Low Risk)
- Reputation: Low Risk
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
- Abuse Confidence Score: Not applicable
The IP demonstrates stable infrastructure characteristics with no persistent malicious behavior observed. No known attacker, spam source, or Tor exit node indicators were identified.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **Organization** | Digital Ocean Inc administrator |
| **ASN** | 14061 (DigitalOcean, LLC, US) |
| **BGP Prefix** | 139.59.80.0/20 |
| **Infrastructure Type** | CloudCompute |
| **Service Purpose** | Firewalled / No Services |
| **Is Cloud** | Yes |
| **Is Hosting** | Yes |
| **Is Proxy/VPN/Cdn** | No |
Geolocation Data:
- Country: US
- Region: US-NY (New York)
- City: New York
- Timezone: America/New_York
- DNSSEC Valid: Yes
---
## Network Observations
Control Plane Status
- Origin ASN: 14061
- Route Changes (30 days): 0
- Is Route Stable: No
- Is MOAS (Multiple Origin ASN Source): No
- DNSSEC Valid: Yes
- RPKI State: Not assessed
- IRR Consistency: Not assessed
DNS Analysis
- PTR Hostnames: None
- Forward Resolution: Not confirmed
- Hosted Domains: 0
- Email Authentication (SPF/DMARC): Not configured
- DNSBL Listings: 1 out of 8 total lists
Service Enumeration
- Open Ports: None
- TLS Certificate: Not detected
- HTTP Service: Not detected
- Server Banner: Not detected
---
## Threat Indicators
| Indicator | Status |
|---|---|
| **Known Attacker** | No |
| **Spam Source** | No |
| **Tor Exit Node** | No |
| **Blacklist Count** | 0 |
| **Threat Feeds** | None |
| **Known Campaigns** | None |
| **Pulsedive Risk** | Not assessed |
---
## Observation History (11 observations)
Recent signal observations indicate:
2026-07-29:
- RIR assignment: ARIN (Digital Ocean Inc administrator, abuse@digitalocean.com)
- ASN assignment: 14061, prefix 139.59.80.0/20
- DNSSEC validation: Valid
- DNSBL activity: 1 listing detected with maximum severity "high"
- Geographic data inconsistencies noted (reported in US, IN, and SG across different sources)
Temporal Behavior:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Persistently Malicious: No
---
## Neighborhood Analysis (Subnet: 139.59.90.162/24)
- Neighbor Count: 0
- Abuse Density: 0
- High Risk Neighbors: 0
- Medium Risk Neighbors: 0
- Low Risk Neighbors: 0
- Threat Siblings: 0
The immediate /24 subnet shows no adjacent malicious activity or abuse patterns.
---
## Relationship Graph
- Related Entities: 0
- Associated Subnets: None
- Associated Hostnames: None
- Associated Organizations: None
- Associated Certificates: None
No meaningful relationships were identified in the relationship graph.
---
## Recommended Actions
Based on the risk profile and observed behavior, the following security actions are recommended:
No immediate action required. The IP address demonstrates low-risk characteristics typical of legitimate cloud infrastructure. However, the following considerations apply:
1. DNSBL Monitoring: 1 of 8 DNSBL lists returned a listing. Monitor for changes in blacklist status.
2. Route Stability: Route stability flag is falseโmonitor for any BGP prefix changes.
3. Geographic Inconsistencies: Geo data shows inconsistencies (US, IN, SG). This may indicate multi
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Digital Ocean Inc administrator |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-AP |
| CIDR Block | 139.59.80.0/20 |
| RIR | ARIN |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 37% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 13% | 1 | 1 |
| Overall | 21% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-24 14:25:49 UTC |
| Last Seen | 2026-08-12 18:37:36 UTC |
| Profile Built | 2026-08-12 18:52:36 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.