IPDebrief

198.199.94.79

IP Intelligence Dossier
Your IP: 216.73.217.135
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IPDEBRIEF INTELLIGENCE BRIEFING

Target: 198.199.94.79/32

Classification: Low Risk / Cloud Infrastructure

Date: 2026-06-20

## Executive Summary

IP 198.199.94.79 is a DigitalOcean cloud compute instance hosting web services (HTTP/HTTPS) with minimal threat indicators. The IP presents a risk score of 25 (Low Risk) and operates as a standard web server infrastructure on a cloud provider network.

## Infrastructure Profile

## Network Services & Endpoints

PortProtocolServiceStatus
80TCPHTTPActive
443TCPHTTPSActive
22TCPSSHActive

## Threat Assessment

## Control Plane & Routing

## Temporal Analysis

## Neighborhood Analysis (198.199.94.0/24)

## Historical Observations (2026-06-20)

## Recommended Actions

1. Allow Traffic: Standard web traffic (HTTP/HTTPS) permitted through existing rules

2. Monitor SSH: Port 22 exposure on public cloud is expected; ensure no unauthorized access attempts

3. DNSBL Review: Investigate single DNSBL listing cause if blocking outbound traffic

4. No Blocking Required: Risk score 25 indicates no immediate threat requiring blocking

## SOC Analyst Notes

This IP represents benign cloud hosting infrastructure. The 502 errors observed in historical traffic may indicate temporary service issues rather than malicious activity. The presence of a single DNSBL listing warrants routine monitoring but does not constitute a threat indicator. No evidence of command-and-control, scanning, or attack behavior detected.

---

Intel Source: IPDebrief Intelligence Platform

Confidence Level: High (Based on 20+ observations)

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionCA
CitySan Francisco
Timezoneβ€”
Latitude37.73
Longitude-122.38

🏒 Ownership & Registration

OrganizationDigitalOcean, LLC
ASNAS14061
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFPresent
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Servernginx/1.4.6 (Ubuntu)
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_6.6.1p1 Ubuntu-2ubuntu2.8

πŸ” TLS Certificate

An expired certificate for CN=odoo.casaria.net was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.
πŸ”’
CN=odoo.casaria.net
Issued by CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US
Self-signed: No
SANsesupport.casaria.neteval.casaria.netnd.casaria.netodoo.casaria.netpad.casaria.net
Valid From2017-07-10T04:04:00+00:00
Valid Until2017-10-08T04:04:00+00:00 (expired)
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period90 days
Serial Number032D074C42C8A8E4F7A0A33D5977EA736B13
Thumbprint4019E4DECF45C3EABF8134226DBA06658AD21C58

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
24
routing
8%
11
services
30%
23
ownership
24%
23
reputation
26%
13
geolocation
33%
23
Overall25%1017
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-20 22:12:44 UTC
Last Seen2026-06-28 12:38:53 UTC
Profile Built2026-06-29 06:44:58 UTC
Data FreshnessLive
Signal Types21
Total Observations24
πŸ” 21 signal types Β· 24 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.