# Intelligence Briefing: 206.189.196.244/32
Date: 2026-08-13
Classification: Moderate Risk (Score: 50)
Provider: DigitalOcean, LLC
---
## Executive Summary
IP address 206.189.196.244 was assessed with a moderate risk score of 50. The address is classified as cloud compute infrastructure with no open services detected. While currently clean, the IP exhibits moderate risk indicators including DNSBL listings and geolocation validation limitations.
## Ownership and Infrastructure
- Organization: DigitalOcean, LLC
- ASN: 14061
- Network: DIGITALOCEAN-206-189-0-0
- CIDR Block: 206.189.0.0/16
- Location: North Bergen, New Jersey, US
- Infrastructure Type: Cloud Compute
- Status: Firewalled / No Services Detected
The IP resolved to a DigitalOcean cloud infrastructure endpoint with no active services. DNS records show no forward confirmation, and no hosted domains or email authentication (SPF/DMARC) were observed.
## Threat Assessment
| Indicator | Status |
|---|---|
| Risk Score | 50 (Moderate) |
| Abuse Confidence | Not Available |
| Blacklist Count | 0 |
| DNSBL Listed | 2 of 8 |
| Is Tor Exit | No |
| Is Known Attacker | No |
| Is Spam Source | No |
| Threat Persistence | Not Persistent |
Threat indicators returned empty across all threat feeds. No known campaigns, malicious scans, or attack attribution were identified. The IP is not classified as a persistent threat actor.
## Historical Context
Fifteen observation signals recorded as of 2026-08-13:
- Classification History: Consistently reported as "clean"
- Abuse Density: 0.0
- Threat Observation Count: 0
- Geo Validation: ICMP blocked; geolocation could not be validated via active probing
- Ownership Stability: No ownership changes detected
The IP has demonstrated stable characteristics with no escalation in threat profile over the observation period.
## Neighborhood Analysis
Subnet: 206.189.196.244/24
- Abuse Density: 0.0
- Risk Classification: Clean
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 0
No neighboring IPs in the /24 subnet showed elevated risk. The subnet exhibits minimal inherited risk from surrounding addresses.
## Recommended Security Actions
Based on the moderate risk assessment, the following controls are recommended:
| Platform | Recommendation |
|---|---|
| iptables | `iptables -A INPUT -s 206.189.196.244 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 206.189.196.244 drop` |
| nginx | `deny 206.189.196.244;` |
| pfSense | Block 206.189.196.244/32 |
| Cloudflare WAF | Block IP with risk score 50 |
| AWS WAF | Add 206.189.196.244/32 to block list |
## Operational Notes
- The IP is part of a large cloud provider network (DigitalOcean 206.189.0.0/16)
- DNSBL listings suggest prior reputation concerns
- No active services detected; traffic patterns may be minimal or firewalled
- Correlated IPs: None identified
- Certificates: No SSL/TLS certificates associated
---
Assessment: The IP 206.189.196.244 presents a moderate risk profile suitable for defensive blocking. While not classified as a known threat actor, the DNSBL listings and moderate risk score warrant filtering. Continuous monitoring is recommended given the cloud infrastructure context.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-206-189-0-0 |
| CIDR Block | 206.189.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-06 12:48:04 UTC |
| Last Seen | 2026-08-13 09:04:12 UTC |
| Profile Built | 2026-08-13 09:13:10 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.