IP INTELLIGENCE BRIEFING
Target: 146.190.126.213/32
Classification: Moderate Risk Infrastructure
---
EXECUTIVE SUMMARY
IP address 146.190.126.213 is a cloud-hosted server located in Santa Clara, CA, operated by DigitalOcean, LLC. The address carries a risk score of 55, indicating moderate risk primarily due to DNSBL listings. The IP is hosted on DigitalOcean's cloud infrastructure (ASN 14061) and is associated with the domain djialajmikw.com via Let's Encrypt certificate.
---
OWNERSHIP & GEOLOCATION
- Organization: DigitalOcean, LLC
- ASN: 14061
- Country: United States (US)
- Region: California (CA)
- City: Santa Clara
- CIDR Block: 146.190.112.0/20 (BGP prefix)
- Geolocation Consensus: Confirmed across 1 source
---
NETWORK CLASSIFICATION
- Infrastructure Type: Cloud Compute
- Cloud Provider: DigitalOcean
- Connection Type: Hosted Server
- Risk Level: Moderate (55/100)
- DNSBL Status: Listed on 3 of 8 threat feeds
- Control Plane Stability: Route changes observed in past 30 days; not route-stable
---
SERVICES & FINGERPRINTING
| Port | Protocol | Service |
|---|---|---|
| 80 | TCP | HTTP |
| 443 | TCP | HTTPS |
| 22 | TCP | SSH |
- Web Server: nginx/1.24.0 (Ubuntu)
- TLS Certificate: Issued by Let's Encrypt (CN=E8, O=Let's Encrypt, C=US)
- Certificate Subject: djialajmikw.com
- SANs: djialajmikw.com, www.djialajmikw.com
- HTTP/2: Enabled
- HSTS/CSP Headers: Not configured
---
THREAT INDICATORS
- Abuse Confidence Score: Not computed
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Campaign Likelihood: None
- Cert Matches: 0
- Banner Matches: 0
---
OBSERVATION HISTORY
- Total Observations: 22
- Most Recent: 2026-06-20T07:30:46 UTC
- DNSBL Listings: 2 of 8 lists flagged as high severity
- Operator Score: 0.1304 (Minimal)
- Subnet Abuse Density: 1 (observed 2026-06-15)
- Threat Persistence: 0 days
- Ownership Changes: 0
---
RELATIONSHIP ANALYSIS
- Related Entities: 18 relationships identified
- Network Associations: 18 instances mapped to "DO-13" network identifier
- No External Certificate/Hostname Associations: Relationships limited to same-network mappings
---
NEIGHBORHOOD ASSESSMENT
- Subnet: 146.190.126.24/24
- Active Siblings: 1
- Threat Siblings: 1
- Overall Classification: Mostly clean
- Inherited Risk Score: 2
---
RECOMMENDED ACTIONS
1. Monitor DNSBL Activity: Three DNSBL listings require continued monitoring for campaign correlation
2. Certificate Review: Domain djialajmikw.com warrants verification of business legitimacy
3. SSH Access: Port 22 open to public; evaluate necessity of blocking if not required
4. Route Stability: Network shows routing changes in past 30 days; monitor for infrastructure instability
5. Geolocation Validation: 8,857.7km distance from probe origin; standard for cloud hosting
---
SOC ANALYST NOTES
This IP represents legitimate cloud hosting infrastructure with moderate risk due to DNSBL associations. The domain djialajmikw.com should be validated against threat intelligence feeds. No active malicious campaigns or known attacker indicators detected. Recommended for monitoring rather than immediate blocking.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | djialajmikw.comwww.djialajmikw.com |
| Valid From | 2026-05-15T16:38:27+00:00 |
| Valid Until | 2026-08-13T16:38:26+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 055CD7E86BBC4383FBE3B2DFCBCC062220C5 |
| Thumbprint | 71CDC49D7299CBC1CB951A9588778877468B0729 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 25% | 10 | 17 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-19 21:39:12 UTC |
| Last Seen | 2026-06-28 09:38:09 UTC |
| Profile Built | 2026-06-29 03:43:35 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.