# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 198.199.94.79/32
Classification: Low Risk / Cloud Infrastructure
Date: 2026-06-20
## Executive Summary
IP 198.199.94.79 is a DigitalOcean cloud compute instance hosting web services (HTTP/HTTPS) with minimal threat indicators. The IP presents a risk score of 25 (Low Risk) and operates as a standard web server infrastructure on a cloud provider network.
## Infrastructure Profile
- Organization: DigitalOcean, LLC (ASN 14061)
- Network: 198.199.92.0/22
- Location: United States (San Francisco consensus)
- Infrastructure Type: Cloud Compute (DigitalOcean Hosting)
- Service Role: Web Server
- Operating System: Ubuntu (nginx 1.4.6)
## Network Services & Endpoints
| Port | Protocol | Service | Status |
|---|---|---|---|
| 80 | TCP | HTTP | Active |
| 443 | TCP | HTTPS | Active |
| 22 | TCP | SSH | Active |
- TLS Certificate: Let's Encrypt Authority X3
- Certificate Subject: odoo.casaria.net
- Associated Domains: esupport.casaria.net, eval.casaria.net, nd.casaria.net, pad.casaria.net
## Threat Assessment
- Risk Score: 25 (Low Risk)
- Known Campaigns: None
- Blacklist Count: 0
- DNSBL Status: Listed on 1 of 8 threat feeds
- Tor/VPN/Proxy: Not detected
- Abuse Confidence: Not flagged as known attacker
## Control Plane & Routing
- BGP Origin: 198.199.92.0/22
- RPKI Validation: Not validated
- DNSSEC: Valid
- Route Stability: Unstable (1 route change in 30 days)
- Operator Score: 0.1304 (Minimal)
## Temporal Analysis
- Threat Persistence: 0 days
- Threat Observations: 1
- Persistently Malicious: No
- Ownership Stability: No recent changes
## Neighborhood Analysis (198.199.94.0/24)
- Abuse Density: 1
- Classification: Mostly Clean
- Active Siblings: 1
- Threat Siblings: 1
- Subnet Risk: Low (Inherited Risk: 2)
## Historical Observations (2026-06-20)
- HTTP responses showing 502 errors
- Server fingerprint: nginx/1.4.6 (Ubuntu)
- SSL/TLS headers present
- No cache headers detected
- Content-Type headers present
## Recommended Actions
1. Allow Traffic: Standard web traffic (HTTP/HTTPS) permitted through existing rules
2. Monitor SSH: Port 22 exposure on public cloud is expected; ensure no unauthorized access attempts
3. DNSBL Review: Investigate single DNSBL listing cause if blocking outbound traffic
4. No Blocking Required: Risk score 25 indicates no immediate threat requiring blocking
## SOC Analyst Notes
This IP represents benign cloud hosting infrastructure. The 502 errors observed in historical traffic may indicate temporary service issues rather than malicious activity. The presence of a single DNSBL listing warrants routine monitoring but does not constitute a threat indicator. No evidence of command-and-control, scanning, or attack behavior detected.
---
Intel Source: IPDebrief Intelligence Platform
Confidence Level: High (Based on 20+ observations)
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.4.6 (Ubuntu) |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_6.6.1p1 Ubuntu-2ubuntu2.8 |
π TLS Certificate
CN=odoo.casaria.net was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.| SANs | esupport.casaria.neteval.casaria.netnd.casaria.netodoo.casaria.netpad.casaria.net |
| Valid From | 2017-07-10T04:04:00+00:00 |
| Valid Until | 2017-10-08T04:04:00+00:00 (expired) |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 90 days |
| Serial Number | 032D074C42C8A8E4F7A0A33D5977EA736B13 |
| Thumbprint | 4019E4DECF45C3EABF8134226DBA06658AD21C58 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 25% | 10 | 17 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-20 22:12:44 UTC |
| Last Seen | 2026-06-28 12:38:53 UTC |
| Profile Built | 2026-06-29 06:44:58 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.