# IP Intelligence Briefing: 159.203.61.235
Classification: Low Risk / Cloud Infrastructure
Date: Current Assessment
Analyst: Automated Intelligence System
---
## Executive Summary
IP 159.203.61.235 is a DigitalOcean cloud infrastructure endpoint located in Toronto, Ontario, Canada. Current risk assessment indicates low threat level (risk score: 25/100). No active threat indicators, spam sources, or known attacker signatures detected.
---
## Infrastructure Profile
- Provider: DigitalOcean, LLC (ASN 14061)
- Network Role: Cloud Compute / Web Server / Hosting
- Geolocation: Toronto, ON, CA (GeoPlausible: FALSE)
- BGP Prefix: 159.203.56.0/21
- Route Stability: Stable (no changes in 30 days)
- Control Plane: RPKI Valid, IRR Consistent
---
## Network Services
- Open Ports: TCP/80 (HTTP), TCP/443 (HTTPS)
- TLS Certificate: Let's Encrypt (CN=*.i.db.ondigitalocean.com)
- HTTP Status: 302 Redirect
- HTTP/2: Enabled
- HSTS: Present (max-age=31536000)
---
## Threat Intelligence
- Abuse Confidence Score: Not Calculated
- Blacklist Status: Clean (0 DNSBL listings)
- Campaign Association: None
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
---
## Neighborhood Analysis
- Subnet: 159.203.61.235/24
- Abuse Density: 0
- Classification: Mostly Clean
- High Risk Neighbors: 0
- Medium Risk Neighbors: 0
---
## Observation History
- Total Signals: 28 observations
- Recent Activity: June 14-19, 2026
- Threat Persistence: 0 days
- Notable Signals:
- 2026-06-19: Geolocation signal with threat indicators (confidence 0.75)
- 2026-06-14: Network classification (Cloud Compute), HTTP fingerprinting, RTT validation anomalies
---
## GeoValidation Warning
Flagged Anomaly: RTT measurement (41.0ms) is below minimum theoretical distance (121.6ms) for claimed Toronto location. Distance calculation: 6078.4km. This discrepancy suggests geolocation data may be inaccurate or spoofed.
---
## Recommended Actions
No immediate blocking or mitigation actions recommended based on current risk profile. Standard monitoring practices advised.
---
## SOC Analyst Notes
This IP operates within DigitalOcean's cloud infrastructure and exhibits typical web server behavior. The geolocation validation flag requires attention but does not indicate malicious activity. No correlation with known threat campaigns or persistent malicious behavior observed.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | โ |
| CIDR Block | 159.203.56.0/21 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | *.i.db.ondigitalocean.com |
| Valid From | 2026-05-03T13:24:59+00:00 |
| Valid Until | 2026-08-01T13:24:58+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 06F3DF107054118796CE627D4D080E4A07D9 |
| Thumbprint | 080B70E06EFC332A4949A91D42AFB51ECF3E08E4 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 22% | 2 | 4 |
| routing | 27% | 3 | 4 |
| services | 24% | 2 | 3 |
| ownership | 27% | 3 | 4 |
| reputation | 26% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 27% | 13 | 21 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-15 08:43:17 UTC |
| Last Seen | 2026-06-28 01:59:41 UTC |
| Profile Built | 2026-06-28 20:04:40 UTC |
| Data Freshness | Live |
| Signal Types | 29 |
| Total Observations | 33 |
Full dossier details are available via our API.