IP INTELLIGENCE BRIEFING: 68.183.43.38
Classification: Moderate Risk | Date: 2026-06-29
---
EXECUTIVE SUMMARY
IP 68.183.43.38 is a DigitalOcean cloud compute instance hosting web services (HTTP/HTTPS) with Apache web server. Risk score of 40 indicates moderate risk, primarily driven by DNSBL listings and unstable routing. The IP is associated with Portuguese domain airluso.pt. No active malicious campaigns detected.
---
OWNERSHIP & GEOLOCATION
- Organization: DigitalOcean, LLC (ASN: 14061)
- Network: DIGITALOCEAN-68-183-0-0 (68.183.0.0/16)
- Geolocation: Slough, England, GB
- Infrastructure: Cloud compute hosting environment
---
THREAT INDICATORS
- Risk Score: 40/100 (Moderate)
- Blacklist Count: 0
- DNSBL Listed: 2 of 8 checked lists
- Known Campaigns: None identified
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Control Plane Risk:
- Route stability: Unstable (isRouteStable: false)
- DNSSEC: Valid
- RPKI: Not evaluated
- Route changes (30d): 0
---
NETWORK SERVICES
- Open Ports: 80/tcp (HTTP), 443/tcp (HTTPS), 22/tcp (SSH)
- Web Server: Apache/2.4.63 (Ubuntu)
- TLS Certificate: Let's Encrypt (R10) for www.airluso.pt
- Email Authentication: No SPF/DMARC configured
---
NEIGHBORHOOD ANALYSIS (68.183.43.0/24)
- Subnet Classification: Mostly clean
- Abuse Density: 1 (low)
- Total Siblings: 1 active neighbor (68.183.43.59, risk score: 0)
- Threat Siblings: 1 identified threat IP in subnet
- Recommendation: Monitor subnet 68.183.43.0/24 for correlated activity
---
HISTORICAL OBSERVATIONS
- Total Signals: 23 observations
- Risk Trend: Stable moderate risk
- Operator Score: 0.1304 (Minimal)
- Recent Activity: Signals observed as recently as 2026-06-29
---
SOC ACTIONS
1. Monitor: Track DNSBL listing changes for 68.183.43.38
2. Block/Alert: If subnet 68.183.43.0/24 shows increased abuse density
3. Investigate: Correlate with other IPs from airluso.pt domain
4. Allow: No immediate blocking recommended for inbound traffic; monitor SSH port 222
Assessment: This is a legitimate cloud hosting instance with minimal threat indicators. The moderate risk score reflects DNSBL presence rather than confirmed malicious activity. No immediate defensive action required beyond standard monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-68-183-0-0 |
| CIDR Block | 68.183.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Apache/2.4.63 (Ubuntu) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.13 |
๐ TLS Certificate
CN=www.airluso.pt was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.| SANs | www.airluso.pt |
| Valid From | 2025-05-10T02:21:24+00:00 |
| Valid Until | 2025-08-08T02:21:23+00:00 (expired) |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 06421413652EF45AA267F389F8A21EA2B314 |
| Thumbprint | 42D8E09D4A389A11855A94E539424118BC2D28B4 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 27% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-28 18:35:23 UTC |
| Last Seen | 2026-06-29 05:54:33 UTC |
| Profile Built | 2026-06-29 06:03:21 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 23 |
Full dossier details are available via our API.