## IP Intelligence Briefing: 206.189.5.249/32
Executive Summary
IP 206.189.5.249 is a DigitalOcean cloud compute resource assigned to the DIGITALOCEAN-206-189-0-0/16 block. The address presents moderate risk (score: 50) with no active threat indicators. The IP is currently firewalled with no open services detected and no open ports.
Ownership & Infrastructure
- Provider: DigitalOcean, LLC
- ASN: 14061
- CIDR Block: 206.189.0.0/16
- Infrastructure Type: CloudCompute
- Location: Amsterdam, NH, US
- Geolocation Confidence: High (plausible with 2500km radius accuracy)
Network Classification
- Classification: Firewalled / No Services
- Open Ports: None detected
- DNS PTR Record: portscanner-ams3-03.prod.cyberresilience.io
- Forward Resolution: Confirmed to portscanner-ams3-03.prod.cyberresilience.io
- Email Authentication: SPF and DMARC records present
- DNSBL Status: Listed on 2 of 8 threat feeds
Neighborhood Analysis
The /24 subnet (206.189.5.0/24) shows a clean abuse profile:
- Abuse Density: 0
- Subnet Classification: Clean
- Total Siblings: 2 active IPs
- Threat Siblings: 0
- Neighbor IP: 206.189.5.117 (risk score: 25, authority score: 50)
Threat Indicators
- Risk Score: 50 (Moderate)
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0
- Campaign Association: None detected
- Threat Persistence: 0 days observed
- Is Persistently Malicious: No
Relationship Graph
The IP maintains 29 relationships with:
- Network Associations: DIGITALOCEAN-206-189-0-0 (multiple entries)
- DNS Associations: portscanner-ams3-03.prod.cyberresilience.io (hostname)
Observation History
Twenty-two observations recorded since deployment. Recent activity includes:
- Network classification updates (June 21, 2026)
- Geolocation confirmations (US-based)
- Operator scoring assessments (score: 0.3478, label: Basic)
- Banner analysis with no malicious patterns detected
Recommended Security Actions
Despite the moderate risk classification, the IP shows no active threat behavior. However, the following defensive rules are available for implementation:
Firewall Rules:
- iptables: `iptables -A INPUT -s 206.189.5.249 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 206.189.5.249 drop`
- nginx: `deny 206.189.5.249;`
WAF Integration:
- Cloudflare WAF: Block IP with filter expression `ip.src eq 206.189.5.249`
- AWS WAF: Add 206.189.5.249/32 to IP Set for blocking
Intelligence Assessment
This DigitalOcean IP represents low-to-moderate risk with no active malicious indicators. The hostname association with "cyberresilience.io" suggests legitimate infrastructure usage. The DNSBL listings (2 of 8) warrant monitoring but do not indicate confirmed malicious activity. The subnet exhibits clean abuse characteristics with no threat siblings. SOC analysts should treat this as a monitored but not actively threatening IP, with recommendation to block only if correlated with specific incident data.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-206-189-0-0 |
| CIDR Block | 206.189.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | portscanner-ams3-03.prod.cyberresilience.io |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | portscanner-ams3-03.prod.cyberresilience.io |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 24% | 2 | 3 |
| Overall | 21% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-30 06:22:35 UTC |
| Last Seen | 2026-06-29 07:15:21 UTC |
| Profile Built | 2026-06-29 07:24:04 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.