IP INTELLIGENCE BRIEFING: 178.128.238.2
CLASSIFICATION: Cloud Infrastructure Asset
REPORT DATE: July 31, 2026
RISK SCORE: 50 (Moderate Risk)
---
**1. OWNERSHIP & INFRASTRUCTURE**
The IP address 178.128.238.2 is hosted on DigitalOcean infrastructure (ASN 14061) within the 178.128.224.0/20 CIDR block. Geolocation data places the asset in Toronto, Ontario, CA. The infrastructure is classified as a cloud compute environment with hosting services enabled.
**2. NETWORK SERVICES & EXPOSURE**
Active service enumeration reveals:
- Port 443/TCP: HTTPS service operational
- Port 22/TCP: SSH service active (OpenSSH_9.6p1 Ubuntu-3ubuntu13.18)
- TLS Certificate: Issued to FieldEffect (vmetrics), Ottawa, ON, CA. Certificate is not self-signed and uses TLS 1.3 with cipher suite TLS_AES_256_GCM_SHA384.
**3. THREAT POSTURE**
Current threat indicators show no active malicious campaigns. The IP is not identified as a known attacker, Tor exit node, proxy, or spam source. However, the asset appears listed on 2 out of 8 queried DNSBLs (DNSBL Listed Count: 2), which contributes to the moderate risk rating. No known threat campaigns correlate with this IP.
**4. CONTROL PLANE ANALYSIS**
Route stability is flagged as false, indicating potential BGP route changes. RPKI validation state is unavailable. The operator score is minimal (0.1304), suggesting low-level operator intervention. DNSSEC validation is confirmed as valid.
**5. NEIGHBORHOOD ANALYSIS**
The /24 subnet (178.128.238.0/24) demonstrates clean abuse density (0.0). Analysis of 1 neighboring IP (178.128.238.30) shows a low-risk profile (risk score: 25, authority score: 50), indicating the subnet is not broadly associated with malicious activity.
**6. OBSERVATION HISTORY**
Signal observation history contains 14 observations. Recent activity on July 31, 2026, confirms:
- Ownership consistently attributed to DigitalOcean
- TLS certificate validation successful
- Connection attempts recorded with successful resolution
- No persistent malicious behavior detected over observation period
**7. RELATIONSHIP GRAPH**
Relationship analysis identifies the IP as belonging to the DIGITALOCEAN network. Two network-level relationships exist, both pointing to the same cloud provider.
**8. SECURITY RECOMMENDATIONS**
Based on risk profile, the following actions are recommended:
- Block SSH access (Port 22): External SSH access from cloud instances is generally unnecessary for web-facing workloads
- Monitor DNSBL listings: Investigate why the IP appears on 2 of 8 DNSBLs; may indicate reputation issues requiring remediation
- Continue passive monitoring: No immediate blocking required, but maintain monitoring for reputation degradation
---
SUMMARY: The IP 178.128.238.2 is a DigitalOcean cloud compute instance with moderate risk scoring primarily due to DNSBL listings. No active malicious indicators or known campaigns are associated. The subnet environment remains clean. Recommended actions focus on SSH access restriction and DNSBL investigation rather than immediate blocking.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | digitalocean |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN |
| CIDR Block | 178.128.224.0/20 |
| RIR | RIPE |
| Country | CA |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
π TLS Certificate
| SANs | 127.0.0.1 |
| Valid From | 2023-09-14T09:32:22+00:00 |
| Valid Until | 2033-09-11T09:32:22+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 3650 days |
| Serial Number | 1CA878DB51BEC9589B48D9BDC5CF39781DF8E32D |
| Thumbprint | 514A23A474F3F9E91A693B8E32F02B2EECE27D54 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 42% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 35% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 21% | 1 | 2 |
| geolocation | 13% | 1 | 1 |
| Overall | 25% | 9 | 13 |
| Data Coherence | Mixed Signals (68%) β 2 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
β TLS certificate claims CA but primary geo says US
π Observation Timeline π Live
| First Seen | 2026-07-30 11:03:28 UTC |
| Last Seen | 2026-08-13 00:35:46 UTC |
| Profile Built | 2026-08-13 00:39:12 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.