IP Intelligence Briefing: 128.199.216.104
Date: 2026-06-14
---
**1. Core Profile**
- Risk Assessment:
- Overall Risk Score: 25 (Low Risk)
- Provider Score: 0 (DigitalOcean, cloud infrastructure)
- Threat Indicators: None detected (no malware, phishing, or C2 activity).
- Geolocation: Singapore (SG), ASN 14061, owned by DigitalOcean.
- Network Role: Cloud-hosted web server (nginx/1.14.0), SSH accessible.
---
**2. Threat & Vulnerability Context**
- Malicious Activity:
- No abuse confidence, Tor exit, or spam indicators.
- SSL certificate valid (Letβs Encrypt, subject: *qualitypackenterprising.lk*).
- Services:
- HTTP/HTTPS (ports 80/443), SSH (port 22).
- Server banner: `nginx/1.14.0 (Ubuntu)`.
- TLS Security:
- No HSTS, CSP, or HTTP/2 enabled.
---
**3. Observation History**
- Stability:
- No significant changes in geolocation, DNS, or threat signals over the past 30 days.
- Single observation event (June 5, 2026) with consistent HTTP response (200 OK).
- Anomalies:
- No sudden spikes in risk or network activity.
---
**4. Network Relationships**
- Subnet: 128.199.216.104/24 (DigitalOcean infrastructure).
- Neighbors:
- No active neighboring IPs in the subnet (0 siblings).
- Subnet abuse density: 0% (clean).
- Provider Context:
- Part of DigitalOceanβs cloud network (ASN 14061).
---
**5. Recommendations**
- Monitoring:
- Track DNS and TLS certificate validity, as the certificate is tied to a domain (*qualitypackenterprising.lk*).
- Monitor for unexpected SSH access or service changes.
- Mitigation:
- No immediate action required due to low risk.
- Ensure firewall rules restrict access to necessary ports (e.g., allow SSH only from trusted ranges).
---
Conclusion: 128.199.216.104 is a low-risk, cloud-hosted web server with no malicious activity detected. No urgent action is required, but ongoing monitoring is advised.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | digitalocean |
| ASN | AS14061 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | 1/2 domains |
| DMARC | 0/2 domains |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.14.0 (Ubuntu) |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_7.6p1 Ubuntu-4ubuntu0.5 |
π TLS Certificate
| SANs | qualitypackenterprising.lk |
| Valid From | 2026-05-26T09:55:09+00:00 |
| Valid Until | 2026-08-24T09:55:08+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 0670B4397F3F6279EB9C8C80D152931DAB7C |
| Thumbprint | 47026782FBF22369819C8D02650CB535BD0E6795 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 28% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 25% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-10 04:11:27 UTC |
| Last Seen | 2026-06-27 16:48:06 UTC |
| Profile Built | 2026-06-28 10:53:25 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 26 |
Full dossier details are available via our API.