# IP INTELLIGENCE BRIEFING
Target: 128.199.142.124/32
Classification: Moderate Risk Cloud Infrastructure
Date: Current Intelligence Cycle
Status: Active Monitoring Recommended
---
## EXECUTIVE SUMMARY
IP address 128.199.142.124 is a DigitalOcean cloud compute instance operating from Singapore with a risk score of 65/100. The IP exhibits characteristics of hosted cloud infrastructure with elevated monitoring activity and multiple DNSBL listings. No active malicious campaigns or known attacker associations detected.
---
## INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| **ASN** | 14061 (DigitalOcean) |
| **Organization** | DigitalOcean |
| **Geolocation** | Singapore (SG) |
| **Infrastructure Type** | CloudCompute |
| **Network Classification** | Single-Service Host |
| **Control Plane** | Route stable (6939 β 14061) |
---
## THREAT INDICATORS
- DNSBL Listings: 3 of 8 total lists
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Campaign Association: None detected
- Blacklist Severity: High (per recent observation)
---
## OBSERVATION HISTORY
29 total observations recorded. Key findings:
- Recent blacklist activity detected (2026-06-22)
- Persistent Apache/2.4.52 web server fingerprint
- HTTP 301 redirect behavior observed
- Multiple signal types including DNSSEC validation, BGP routing stability, and service enumeration
---
## NEIGHBORHOOD ANALYSIS
Subnet: 128.199.142.124/24
Abuse Density: 0
Classification: Mostly Clean
Threat Siblings: 1 detected
---
## NETWORK SERVICES
| Port | Protocol | Service |
|---|---|---|
| 22 | TCP | SSH (OpenSSH_8.9p1 Ubuntu-3ubuntu0.15) |
Server banner indicates Apache/2.4.52 with HTTP/1.1 support, no HTTP/2 enabled.
---
## RECOMMENDED ACTIONS
Immediate
1. Increase logging verbosity and review recent activity from this IP source
2. Monitor for reconnaissance patterns given the SSH exposure
Firewall Rules
```bash
# iptables
iptables -A INPUT -s 128.199.142.124 -j DROP
# nftables
nft add rule inet filter input ip saddr 128.199.142.124 drop
# Cloudflare WAF
ip.src eq 128.199.142.124 β block
# AWS WAF
Addresses: ["128.199.142.124/32"] β Block
```
---
## SOC INTELLIGENCE NOTES
This IP represents a legitimate cloud infrastructure endpoint with elevated risk classification primarily driven by DNSBL listings and moderate reputation factors. The DigitalOcean hosting environment suggests potential for compromised tenant instances. Implement monitoring rather than immediate blocking to maintain visibility on activity patterns.
Priority: Medium
Action Window: 30 days (monitor for escalation)
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | digitalocean |
| ASN | AS14061 |
| Network Name | β |
| CIDR Block | 128.199.128.0/18 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | Apache/2.4.52 |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 17% | 2 | 3 |
| services | 25% | 2 | 4 |
| ownership | 22% | 3 | 4 |
| reputation | 26% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 23% | 12 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:39 UTC |
| Last Seen | 2026-06-26 22:06:11 UTC |
| Profile Built | 2026-06-27 18:20:04 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 32 |
Full dossier details are available via our API.