# IP Intelligence Briefing: 198.199.90.202/32
Classification: Low Risk | Risk Score: 25 | Provider: DigitalOcean, LLC
## Executive Summary
IP 198.199.90.202 is a cloud-compute host registered to DigitalOcean (ASN 14061), located in North Bergen, NJ. The asset presents a low-risk profile (score 25) with no active threat indicators. However, geolocation validation anomalies and historical HTTP 500 errors warrant monitoring.
## Technical Profile
| Attribute | Value |
|---|---|
| **Organization** | DigitalOcean, LLC (ASN 14061) |
| **Infrastructure Type** | Cloud Compute / Hosting |
| **Geolocation** | US (NJ, North Bergen) - *Validation Issue* |
| **Open Ports** | 80/tcp (HTTP), 443/tcp (HTTPS), 22/tcp (SSH) |
| **Web Server** | nginx/1.18.0 (Ubuntu) |
| **TLS Certificate** | Let's Encrypt (CN=mamura.ptsystems.net) |
| **DNSBL Listings** | 1 of 8 total lists |
## Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Proxy/VPN: No
- Campaign Association: None detected
- Threat Feeds: Empty
## Geolocation Anomaly
Geolocation validation indicates a significant discrepancy: the IP claims to be in North Bergen, NJ (~40.7964° N, -74.0203° W), but RTT measurements (23ms) are inconsistent with the claimed distance of 5963km (minimum possible RTT should be ~119ms). This suggests either:
- Misconfigured geo-database
- IP hijacking or spoofing
- Misattribution in public databases
## Network Context
Subnet Analysis (198.199.90.0/24):
- Abuse Density: 0%
- Classification: Mostly Clean
- Threat Siblings: 1
- Active Siblings: 1
Network Relationships:
The IP belongs to DigitalOcean's 198.199.64.0/10 address block. No malicious relationships detected with other entities.
## Historical Observations
Timeline: 23 total observations
- Most Recent: 2026-06-20
- HTTP Status: 500 (Internal Server Error) - observed on 2026-06-20
- Ownership Changes: 0
- Threat Persistence Days: 0
- Persistently Malicious: No
## SOC Actionable Recommendations
| Priority | Action | Justification |
|---|---|---|
| **Monitor** | Continue standard traffic monitoring | Low risk score, no active threats |
| **Investigate** | Review HTTP 500 errors for application issues | Indicates service instability, potential abuse vector |
| **Verify** | Confirm geolocation accuracy if critical | RTT/Distance mismatch suggests data integrity issue |
| **Block** | No immediate action required | No actionable threats identified |
## Conclusion
IP 198.199.90.202 is a legitimate DigitalOcean cloud-hosted web server with low-risk characteristics. The primary concern is geolocation validation inconsistency and historical HTTP 500 errors. No immediate threat mitigation required. Include in standard cloud provider monitoring group.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.18.0 (Ubuntu) |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.13 |
π TLS Certificate
| SANs | mamura.ptsystems.net |
| Valid From | 2026-04-17T09:24:54+00:00 |
| Valid Until | 2026-07-16T09:24:53+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 0675DDD6C4B709481C4BDE40D624EA78292D |
| Thumbprint | 2A0D283E059F968D76566DE3A8FDE5E8C085258E |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 25% | 10 | 17 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-20 22:12:44 UTC |
| Last Seen | 2026-06-28 12:38:15 UTC |
| Profile Built | 2026-06-29 06:42:38 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.