# IP INTELLIGENCE BRIEFING
Target: 104.131.120.169/32
Date: 2026-06-14
Classification: Low Risk / Cloud Infrastructure
---
## EXECUTIVE SUMMARY
Intellect profile indicates 104.131.120.169 is a low-risk DigitalOcean cloud compute instance with minimal threat indicators. The IP operates within DigitalOcean's 104.131.0.0/16 network block, located in Clifton, NJ. No active services, open ports, or known malicious activity detected. Neighborhood analysis confirms clean subnet environment with zero abuse density.
---
## RISK ASSESSMENT
| Metric | Value | Classification |
|---|---|---|
| Risk Score | 25 | Low Risk |
| Provider Score | 0 | Clean |
| Authority Score | 0 | Clean |
| Operator Score | 0.1304 | Minimal |
| Stability Score | 0 | N/A |
Risk Breakdown: The IP maintains a stable low-risk profile with no significant threat indicators. Risk persistence days recorded at zero, indicating no persistent malicious behavior observed.
---
## OWNERSHIP & INFRASTRUCTURE
- Provider: DigitalOcean, LLC
- ASN: AS14061
- CIDR Block: 104.131.64.0/18
- Infrastructure Type: Cloud Compute
- Location: Clifton, New Jersey, US (US)
- IP Class: Class A Cloud Infrastructure
- BGP Prefix: 104.131.64.0/18
- Route Stability: Unstable (route changes detected in last 30 days)
---
## THREAT INDICATORS
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Proxy/VPN: False
- CDN: False
- Residential: False
- Blacklist Count: 0
- Campaign Likelihood: None
- Threat Persistence: None
DNSBL Status: Single listing detected across 8 total lists checked (dnsblListedCount: 1). Minimal impact on operational status.
---
## NETWORK SERVICES
- Open Ports: None detected
- TLS Certificate: Not present
- HTTP Title: Not applicable
- DNS Hosted Domains: 0
- Email Auth: SPF/DMARC not configured
- Forward Resolution: 0 records
---
## OBSERVATION HISTORY
Recent signal observations (2026-06-14):
- Geolocation: Multi-signal inference confirms US location with 65% confidence
- Network Classification: Confirmed as DigitalOcean cloud infrastructure (85% confidence)
- Control Plane: Operator score maintained at minimal 0.1304
- Historical Check (2026-06-07): Similar characteristics observed from Clifton, NJ via AlienVault OTX
Temporal Analysis: No ownership changes detected. No threat persistence pattern identified.
---
## RELATIONSHIP GRAPH
The IP maintains 23 relationships, all classified as "Same Network" targeting DIGITALOCEAN-104-131-0-0. This indicates the IP is part of the DigitalOcean 104.131.0.0/16 network block with no external entity associations.
---
## NEIGHBORHOOD ANALYSIS
- Subnet: 104.131.120.169/24
- Abuse Density: 0 (Clean)
- Risk Distribution: High: 0, Medium: 0, Low: 0
- Threat Siblings: 1
- Active Siblings: 1
- Total Siblings: 1
The immediate /24 neighborhood demonstrates minimal abuse activity, with threat inheritance score of 2.
---
## RECOMMENDED ACTIONS
Firewall/Network Policy:
- No blocking recommended based on current risk profile
- Standard cloud instance allow-listing appropriate if legitimate business purpose exists
- Consider monitoring for new service launches or port openings
Threat Intelligence:
- No immediate threat action required
- Monitor for DNSBL listing updates
- Track route stability changes for BGP anomaly detection
SOC Analyst Notes:
This IP represents standard DigitalOcean cloud infrastructure with clean threat posture. Single DNSBL listing warrants periodic review but does not indicate active malicious activity. No correlation with known campaigns or threat actors. Recommend treating as benign unless operational context indicates otherwise.
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 20% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 24% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 19% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-14 07:12:42 UTC |
| Last Seen | 2026-06-28 00:17:05 UTC |
| Profile Built | 2026-06-29 00:22:16 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 25 |
Full dossier details are available via our API.