# IP Intelligence Briefing: 142.93.11.254/32
Classification: Moderate Risk
Date: Current
Analyst: IPDebrief Intelligence Team
Provider: DigitalOcean, LLC (ASN 14061)
## Executive Summary
IP address 142.93.11.254 is a DigitalOcean cloud compute infrastructure endpoint located in New York, US. The asset registers a risk score of 40 (Moderate Risk) with 2 DNSBL listings across 8 total lists. No active threat indicators, known campaigns, or malicious reputation sources were identified. The subnet exhibits low abuse density with a single neighbor IP (142.93.11.100) showing low-risk classification.
## Technical Profile
Ownership & Infrastructure:
- Provider: DigitalOcean, LLC
- ASN: 14061
- CIDR Block: 142.93.0.0/16
- Infrastructure Type: Cloud Compute / Hosting
- Network Role: Firewalled / No Services
Geolocation:
- Country: United States (US)
- Region: New York
- City: New York
- Geographic Validation: Consensus confirmed (plausible)
Network Services:
- Open Ports: None detected
- TLS Certificate: None
- HTTP Title: None
- Forward DNS Resolution: Not confirmed
Threat Indicators:
- Blacklist Count: 2 (of 8 DNSBL lists)
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Abuses Confidence Score: Not available
## Observation History
17 signal observations recorded. Most recent observations (2026-07-30) indicate:
- DNSSEC validation: Valid
- Geo-location validation: ICMP blocked, unable to validate (distance: 5963 km)
- No ownership changes detected
- No persistent malicious behavior patterns
- No threat persistence days recorded
## Relationship Analysis
Relationship graph contains 3 entries, all referencing the same network (DIGITALOCEAN-142-93-0-0). No direct links to hostnames, organizations, or certificates identified.
## Neighborhood Assessment
Subnet: 142.93.11.254/24
- Abuse Density: 0 (Clean)
- Total Siblings: 2
- Active Siblings: 1
- Threat Siblings: 0
- Neighbor IP (142.93.11.100): Risk Score 25 (Low)
Risk distribution in /24 subnet: 1 low-risk, 0 medium-risk, 0 high-risk
## Risk Assessment
Risk Score: 40 (Moderate)
Risk Factors:
- 2 DNSBL listings (high severity)
- Cloud hosting infrastructure (potential for abuse)
- No services exposed (reduces attack surface)
Mitigating Factors:
- No open ports or active services
- No known threat indicators or campaigns
- Low-abuse neighborhood
- Single active neighbor with low-risk classification
## Recommended Actions
Blocking Rules Recommended:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 142.93.11.254 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 142.93.11.254 drop` |
| nginx | `deny 142.93.11.254;` |
| pfSense | `142.93.11.254/32` |
| Cloudflare WAF | Block IP (risk score 40) |
| AWS WAF | Add 142.93.11.254/32 to blacklist |
Monitoring Recommendations:
- Monitor for port scans or service enumeration attempts
- Track DNSBL listing changes
- Observe neighborhood activity for coordinated behavior
- No immediate blocking required if no observed malicious traffic
## Conclusion
IP 142.93.11.254 represents a moderate-risk cloud infrastructure endpoint with DNSBL listings but no active threat indicators. The asset appears to be a legitimate DigitalOcean hosting resource with minimal observed abuse. Blocking recommendations are provided based on DNSBL presence, but operational context should inform final disposition. Continuous monitoring recommended for subnet activity.
---
*This briefing is based on IPDebrief intelligence data. Recommendations should be validated against operational context before implementation.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-142-93-0-0 |
| CIDR Block | 142.93.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-28 22:21:48 UTC |
| Last Seen | 2026-08-13 06:43:51 UTC |
| Profile Built | 2026-08-12 22:57:13 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.