IP Intelligence Briefing: 192.241.179.235
Date: 2026-06-17
---
**1. Core Profile**
- Risk Score: 80 (High Risk)
- Ownership: DigitalOcean, LLC (ASN 14061)
- Geolocation: New York, NY, US
- Network Role: Cloud Compute (DigitalOcean droplet)
- Services:
- Open ports: HTTP (80/tcp), SSH (22/tcp)
- SSH banner: `SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16`
- HTTP redirect (302) to `b2287e5a.tidalcoinage.internet-measurement.com`
---
**2. Threat Indicators**
- No direct malicious activity detected (no known attackers, spam, or blacklists).
- DNS Associations:
- Linked to `b2287e5a.tidalcoinage.internet-measurement.com` (PTR confirmed).
- Subdomain of `internet-measurement.com` (possibly benign research or testing infrastructure).
- BGP/Network:
- Part of DigitalOceanβs `/19` prefix (192.241.160.0/19).
- Subnet abuse density: 1 (mostly clean).
---
**3. Observation History**
- Recent Signals (Last 30 Days):
- Consistent geolocation in New York, US.
- SSH service active with standard OpenSSH banner.
- HTTP service with redirect to a domain with no known malicious history.
- No spikes in threat indicators or DNS anomalies.
- Stability:
- Network stability score: 0 (unstable, likely due to cloud provider dynamics).
- No persistent malicious behavior observed.
---
**4. Relationships**
- Network:
- Same subnet (`192.241.179.0/24`) with 1 active sibling.
- Subnet abuse density: 1 (low risk).
- DNS:
- Resolves to `b2287e5a.tidalcoinage.internet-measurement.com` (no malicious domains detected).
- Organizations:
- Directly linked to DigitalOcean, LLC (cloud hosting provider).
---
**5. Recommendations**
- Monitor SSH Access:
- Track login attempts and ensure multi-factor authentication (MFA) is enabled.
- Inspect DNS Traffic:
- Analyze traffic to `internet-measurement.com` for unusual patterns.
- Network Segmentation:
- Isolate cloud instances to limit lateral movement if compromised.
- Verify DNSSEC:
- Confirm DNSSEC validation is enabled for `internet-measurement.com` to prevent spoofing.
---
**6. Summary**
The IP 192.241.179.235 is a DigitalOcean droplet with no direct malicious indicators. While its high risk score reflects network-level factors (e.g., cloud infrastructure), the IP itself appears legitimate. Focus on monitoring SSH activity and DNS traffic to ensure no covert operations are underway. No immediate mitigation actions required, but continued observation is advised.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | b2287e5a.tidalcoinage.internet-measurement.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | b2287e5a.tidalcoinage.internet-measurement.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 22% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 25% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 21% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:03 UTC |
| Last Seen | 2026-06-27 02:31:00 UTC |
| Profile Built | 2026-06-28 02:38:31 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 28 |
Full dossier details are available via our API.