IPDebrief

192.241.179.235

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP Intelligence Briefing: 192.241.179.235

Date: 2026-06-17

---

**1. Core Profile**

- Open ports: HTTP (80/tcp), SSH (22/tcp)

- SSH banner: `SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16`

- HTTP redirect (302) to `b2287e5a.tidalcoinage.internet-measurement.com`

---

**2. Threat Indicators**

- Linked to `b2287e5a.tidalcoinage.internet-measurement.com` (PTR confirmed).

- Subdomain of `internet-measurement.com` (possibly benign research or testing infrastructure).

- Part of DigitalOcean’s `/19` prefix (192.241.160.0/19).

- Subnet abuse density: 1 (mostly clean).

---

**3. Observation History**

- Consistent geolocation in New York, US.

- SSH service active with standard OpenSSH banner.

- HTTP service with redirect to a domain with no known malicious history.

- No spikes in threat indicators or DNS anomalies.

- Network stability score: 0 (unstable, likely due to cloud provider dynamics).

- No persistent malicious behavior observed.

---

**4. Relationships**

- Same subnet (`192.241.179.0/24`) with 1 active sibling.

- Subnet abuse density: 1 (low risk).

- Resolves to `b2287e5a.tidalcoinage.internet-measurement.com` (no malicious domains detected).

- Directly linked to DigitalOcean, LLC (cloud hosting provider).

---

**5. Recommendations**

- Track login attempts and ensure multi-factor authentication (MFA) is enabled.

- Analyze traffic to `internet-measurement.com` for unusual patterns.

- Isolate cloud instances to limit lateral movement if compromised.

- Confirm DNSSEC validation is enabled for `internet-measurement.com` to prevent spoofing.

---

**6. Summary**

The IP 192.241.179.235 is a DigitalOcean droplet with no direct malicious indicators. While its high risk score reflects network-level factors (e.g., cloud infrastructure), the IP itself appears legitimate. Focus on monitoring SSH activity and DNS traffic to ensure no covert operations are underway. No immediate mitigation actions required, but continued observation is advised.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionNY
CityNew York
Timezoneβ€”
Latitude40.79
Longitude-74.06

🏒 Ownership & Registration

OrganizationDigitalOcean, LLC
ASNAS14061
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRb2287e5a.tidalcoinage.internet-measurement.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesb2287e5a.tidalcoinage.internet-measurement.com

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeMulti-Service Host
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
22sshtcp
Closed Ports25, 443, 3389, 8080, 8443 (2 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
22%
24
routing
8%
11
services
25%
23
ownership
24%
23
reputation
26%
13
geolocation
19%
22
Overall21%1016
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-07 23:04:03 UTC
Last Seen2026-06-27 02:31:00 UTC
Profile Built2026-06-28 02:38:31 UTC
Data FreshnessLive
Signal Types22
Total Observations28
πŸ” 22 signal types Β· 28 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.