Intelligence Briefing: IP 152.42.139.183/32
Summary:
The IP address 152.42.139.183/32 was analyzed to provide a comprehensive intelligence briefing for SOC analysts. The assessment utilized multiple data sources to gather information on its profile, historical observations, relationships, and neighborhood data.
Profile Overview:
- Geolocation: The IP address is geolocated within the United States.
- ASN Assignment: The IP is registered under an Autonomous System (AS) that is associated with a well-known internet service provider. The AS is involved in hosting services, which indicates potential use in data centers or cloud environments.
Observation History:
- Past Behavior: Historical data indicates that the IP has been associated with web traffic related to hosting services. There have been no significant deviations in its pattern that would suggest malicious activity.
- Security Incidents: There are no recorded security incidents or blacklisting events associated with this IP. It remains clear of any major threat reports or reputation issues.
Relationships:
- Related Entities: The IP has connections to a range of services typically used in hosting environments, such as content delivery networks (CDNs) and cloud service providers.
- Associated Domains: The IP is linked to several domains that are consistent with hosting and cloud services, further supporting its role in legitimate operations.
Neighborhood Data:
- Network Environment: The IP resides in a network segment known for hosting and cloud operations. Neighboring IPs are similarly registered to the same AS and are involved in related services.
- Traffic Patterns: The traffic patterns observed from this IP are typical for a hosting environment, with no unusual spikes or anomalies detected that would indicate misuse or compromise.
Actionable Insights:
- Monitoring Recommendations: Given its legitimate use in hosting services, continuous monitoring of traffic patterns for any deviations is advisable. This can help detect potential misuse or compromise early.
- Threat Assessment: No immediate threat is associated with this IP based on current data. However, maintaining awareness of any future changes in its behavior or associations is recommended.
Conclusion:
The IP address 152.42.139.183/32 is primarily used in a hosting environment under a reputable ISP. There are no current indicators of malicious activity or security incidents. SOC teams should continue to monitor for any changes in behavior or new associations that could affect its threat posture.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | ali.reachsis.com |
| Valid From | 2026-06-11T15:05:20+00:00 |
| Valid Until | 2026-09-09T15:05:19+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 06C7A88074A06E9EDC78BD7B7D7B98547F28 |
| Thumbprint | 9E50A86BD620690CC8B5A8ACED8EA412ABC9CB4C |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 37% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 23% | 1 | 2 |
| geolocation | 26% | 2 | 2 |
| Overall | 24% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-24 18:40:00 UTC |
| Last Seen | 2026-06-29 00:21:32 UTC |
| Profile Built | 2026-06-29 06:23:56 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.