IP Intelligence Briefing: 209.38.28.62
*Generated via IPDebrief tools: Profile, History, Relationships, Neighbors*
---
**1. IP Profile**
- Risk Score: Moderate (50/100)
- Ownership:
- ISP: DigitalOcean, LLC (ASN 14061)
- Network: DO-13 (209.38.0.0/16)
- Geolocation:
- Country: US (but flagged as "New South Wales, Sydney" β potential data inconsistency).
- Coordinates: Unresolved (latitude/longitude null).
- Threat Indicators:
- No malicious indicators, blacklists, or campaign associations.
- Network Role: Cloud compute instance (DigitalOcean), no public services or open ports.
- DNS: No PTR records, SPF/DKIM/DNSBL entries.
---
**2. Observation History**
- Recent Signals (2026-06-12):
- DNSSEC Valid: Confirmed.
- Threat Likelihood: "None" (no malicious activity detected).
- Routing: Stable (BGP prefix 209.38.16.0/20).
- Abuse Confidence: 0 (no reported abuse).
- Trend: No persistent threats or anomalous behavior observed.
---
**3. Relationships**
- Linked Entities:
- Network: DO-13 (DigitalOceanβs network).
- No Hostnames/Certificates: No DNS or TLS associations.
- No Campaigns: No correlated IPs or malware families.
---
**4. Subnet Analysis**
- Subnet: 209.38.28.62/24
- Neighbor Risk:
- Abuse Density: 0% (clean subnet).
- Active Siblings: 0 (no neighboring IPs detected).
---
**5. Actionable Insights**
- Geolocation Anomaly: The IPβs geolocation reports "New South Wales, Sydney" (Australia) despite being registered to a US-based provider. Verify if this is a misclassification or spoofed data.
- Monitor for Changes: Track DNSSEC validity and threat signals over time, as the IPβs history shows low confidence in some metrics.
- Network Segmentation: Since itβs a cloud compute instance, ensure itβs isolated in a secure VPC with restricted access.
Conclusion: 209.38.28.62 appears to be a legitimate DigitalOcean cloud instance with no immediate threats. However, the geolocation discrepancy warrants further investigation to rule out spoofing or data errors.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DO-13 |
| CIDR Block | 209.38.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Caddy |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-30 23:04:22 UTC |
| Last Seen | 2026-06-29 08:06:30 UTC |
| Profile Built | 2026-06-29 08:11:56 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.