# IP INTELLIGENCE BRIEFING: 209.97.133.113/32
Classification: Low Risk / Cloud Infrastructure
Date: 2026-06-28
Analyst: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
IP 209.97.133.113 is classified as Low Risk with an overall risk score of 25. The address is associated with DigitalOcean cloud infrastructure deployed in London, England. No active threat indicators, open services, or malicious activity detected. The IP represents legitimate cloud compute infrastructure.
---
## OWNERSHIP & GEOLOCATION
| Attribute | Value |
|---|---|
| **Organization** | DigitalOcean, LLC |
| **ASN** | 14061 |
| **BGP Prefix** | 209.97.128.0/20 |
| **Country** | United Kingdom (GB) |
| **City** | London, ENG |
| **Infrastructure Type** | Cloud Compute |
| **Provider Score** | 80/100 |
Geolocation validation confirms the IP is plausible with geoConsensus=true across multiple sources. Distance from claimed location: 506.4 km from London coordinates.
---
## THREAT ASSESSMENT
| Indicator | Status |
|---|---|
| **Risk Score** | 25 (Low Risk) |
| **Blacklist Count** | 0 |
| **DNSBL Listed** | 1 of 8 lists |
| **Known Attacker** | No |
| **Tor Exit Node** | No |
| **Spam Source** | No |
| **Active Threats** | None |
| **Campaign Correlation** | None |
Threat History: Single threat observation recorded. No persistent malicious activity detected. Threat observation count: 1.
---
## NETWORK SERVICES & DNS
- Open Ports: None detected
- Services: Firewalled / No Services
- DNS Records: No forward resolution, no hosted domains
- Email Authentication: SPF/DMARC not configured
- TLS Certificate: None detected
- HTTP Banner: None detected
---
## NEIGHBORHOOD ANALYSIS
Subnet: 209.97.133.0/24
Abuse Density: 50%
Total Siblings: 2
Active Siblings: 1
Threat Siblings: 1
| Neighbor IP | Risk Score | Classification |
|---|---|---|
| 209.97.133.232 | 25 | Low Risk |
Comparison indicates both IPs share identical provider (DigitalOcean), organization, and country attributes with matching risk scores.
---
## CONTROL PLANE & ROUTING
- Route Stability: Not stable
- Route Changes (30d): 0
- RPKI State: Not available
- DNSSEC Valid: Yes
- IRR Consistency: Not assessed
- Origin ASN: 14061
- Operator Score: 0.1304 (Minimal)
---
## OBSERVATION HISTORY
Total Observations: 19
Recent Activity: 2026-06-20
Key historical signals include:
- Cloud provider identification (DigitalOcean)
- Geolocation inference (GB, London)
- Network role classification (CloudCompute, Firewalled)
- Multiple probe counts confirming geo-plausibility
---
## RECOMMENDED ACTIONS
Security Posture: ACCEPT / MONITOR
1. Blocklist Status: No block required. Risk score (25) indicates low threat level.
2. Firewall Rules: No specific rules required for this IP.
3. Monitoring: Standard monitoring recommended. No elevated threat indicators.
4. Reputation: Maintain current classification as Low Risk.
Rationale: IP belongs to legitimate cloud infrastructure provider (DigitalOcean). No active threat indicators, no open services, no blacklist entries beyond minimal DNSBL presence. Neighbor IP analysis confirms consistent low-risk profile across the subnet.
---
End of Briefing
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 41% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 26% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 15:19:21 UTC |
| Last Seen | 2026-06-28 19:45:46 UTC |
| Profile Built | 2026-06-29 07:49:48 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 22 |
Full dossier details are available via our API.