## IP Intelligence Briefing: 174.138.83.43/32
Classification: Low Risk Cloud Infrastructure Endpoint
Date: 2026-06-20
Executive Summary
IP 174.138.83.43 is a DigitalOcean cloud compute endpoint presenting a low-risk profile (risk score: 25/100) with standard web server services. The IP is hosted in Clifton, NJ, USA within DigitalOcean's 174.138.80.0/20 BGP prefix. While the infrastructure shows minimal abuse characteristics, route stability concerns and DNSBL listing warrant monitoring.
Infrastructure Profile
| Attribute | Value |
|---|---|
| **Organization** | DigitalOcean, LLC (ASN: 14061) |
| **Geolocation** | US, NJ, Clifton |
| **Infrastructure Type** | Cloud Compute / Hosting |
| **Risk Score** | 25 (Low Risk) |
| **Provider Score** | 0 |
| **Authority Score** | 0 |
Network Services & Exposed Ports
The IP presents three open ports:
- Port 80/tcp (HTTP)
- Port 443/tcp (HTTPS)
- Port 22/tcp (SSH)
No TLS certificates, HTTP titles, or server banners were detected. Email authentication records (SPF/DMARC) are absent.
Threat Indicators
- Blacklist Status: Listed on 1 of 8 DNSBLs
- Threat Indicators: None detected
- Known Campaigns: None correlated
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Abuse Confidence Score: Not assigned
Control Plane Analysis
- BGP Prefix: 174.138.80.0/20
- Operator Score: 0.1304 (Minimal)
- Route Stability: False (route changes observed in last 30 days)
- DNSSEC: Valid
- Route Changes (30d): 0
Neighborhood Assessment
The /24 subnet (174.138.83.43/24) shows:
- Abuse Density: 0 (minimal)
- Risk Classification: Mostly clean
- Active Siblings: 1
- Threat Siblings: 1
- Risk Inheritance: 2
Observation History
19 signals observed with the most recent activity on 2026-06-20. Signal types include:
- Network classification (cloud infrastructure confirmed)
- Routing analysis
- Service fingerprinting
- Ownership verification
- Reputation scoring
- Geolocation validation
Geolocation Validation
RTT analysis indicates a potential discrepancy:
- Measured RTT: 23.0ms
- Expected Minimum RTT: 119.4ms (for 5,967km distance)
- Probe Count: 5
- Status: RTT violation detected
Relationships
19 "Same Network" relationship entries identified, all mapping to DIGITALOCEAN-174-138-0-0 network block. No certificate or hostname relationships detected.
Security Assessment
The IP demonstrates characteristics of legitimate cloud hosting infrastructure with minimal threat indicators. However, the following factors warrant defensive monitoring:
1. DNSBL Listing: Presence on 1 blacklist requires validation
2. Route Instability: Route changes detected within the 30-day window
3. SSH Exposure: Port 22 accessible (standard for cloud hosting)
4. Geolocation Anomaly: RTT discrepancy suggests potential misconfiguration or spoofing
Recommended Actions
- Monitor DNSBL listing status for removal
- Verify geographic consistency with traffic patterns
- Apply standard cloud hosting security controls
- No immediate blocking recommended; maintain observation
Analyst Note: This endpoint is consistent with normal DigitalOcean hosting operations. Continued monitoring recommended for route stability and DNSBL status changes.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | β |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 26% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 17 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-22 09:11:52 UTC |
| Last Seen | 2026-06-28 18:20:26 UTC |
| Profile Built | 2026-06-29 06:23:57 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.