IPDebrief

128.199.221.212

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target IP: 128.199.221.212/32

Date: 2026-06-14

Classification: Moderate Risk

---

## EXECUTIVE SUMMARY

IP 128.199.221.212 is a DigitalOcean cloud host located in Singapore operating as a web server. The address carries a moderate risk score of 50, with evidence of DNS blacklist activity and minimal operator reputation. The IP is hosted on cloud infrastructure and resolves to the domain codes.hla-integrated.com. No active threat campaigns or known attacker indicators were identified.

---

## OWNERSHIP & INFRASTRUCTURE

---

## NETWORK SERVICES & DNS

Open Ports:

DNS Resolution:

Security Posture:

---

## THREAT INDICATORS

MetricValue
Risk Score50 (Moderate)
Abuse ConfidenceNot Calculated
Blacklist Count2
Operator Score0.1304 (Minimal)
Known AttackerNo
Tor Exit NodeNo
Campaign Matches0

Control Plane:

---

## HISTORICAL OBSERVATIONS

Total Observations: 25 signals collected

- Cloud infrastructure classification confirmed (DigitalOcean)

- DNS blacklist activity detected with high severity listings

- Operator score assessments completed

---

## NEIGHBORHOOD ANALYSIS

Subnet: 128.199.221.212/24

The subnet shows minimal but present abuse activity, with one related IP flagged as a threat sibling.

---

## RELATIONSHIP GRAPH

---

## RECOMMENDED ACTIONS

Firewall Rules (High Priority)

```bash

# iptables

iptables -A INPUT -s 128.199.221.212 -j DROP

# nftables

nft add rule inet filter input ip saddr 128.199.221.212 drop

```

Web Application Firewall

```nginx

# nginx

deny 128.199.221.212;

# Cloudflare WAF

{"description":"Block 128.199.221.212 β€” IPDebrief risk score 50", "action":"block", "filter":{"expression":"ip.src eq 128.199.221.212"}}

```

AWS WAF

```json

{"Addresses":["128.199.221.212/32"],"Description":"IPDebrief risk 50"}

```

---

## SOC ANALYST NOTES

1. Block Decision: Recommended due to DNS blacklist activity and moderate risk score

2. Geolocation Warning: Singapore assignment flagged as implausible β€” verify actual location

3. Domain Investigation: codes.hla-integrated.com warrants additional scrutiny

4. Monitoring: Track for any escalation in abuse density within the /24 subnet

5. False Positive Consideration: Legitimate hosting environment β€” consider allowing if traffic appears benign

---

Report Generated: IPDebrief Intelligence Platform

Confidence Level: Moderate

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΈπŸ‡¬ Singapore
Regionβ€”
CitySingapore
TimezoneAsia/Singapore
Latitude1.35
Longitude103.82

🏒 Ownership & Registration

Organizationdigitalocean
ASNAS14061
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRcodes.hla-integrated.com
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamescodes.hla-integrated.com

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
443httpstcpβ€”
22sshtcp
Closed Ports25, 80, 3389, 8080, 8443 (2 open / 7 scanned)
Servernginx
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.13

πŸ” TLS Certificate

πŸ”’
CN=codes.hla-integrated.com
Issued by CN=R13, O=Let's Encrypt, C=US
Self-signed: No
SANscodes.hla-integrated.com
Valid From2026-05-01T02:02:34+00:00
Valid Until2026-07-30T02:02:33+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period89 days
Serial Number06E2EA7686CE6BD4DB9C0C09066553402C94
Thumbprint95EF140A636512C7989006A02F5490EBD9CA256B

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
24
routing
8%
11
services
25%
23
ownership
24%
23
reputation
26%
13
geolocation
31%
23
Overall23%1017
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-13 19:03:43 UTC
Last Seen2026-06-27 23:36:36 UTC
Profile Built2026-06-28 23:41:53 UTC
Data FreshnessLive
Signal Types23
Total Observations28
πŸ” 23 signal types Β· 28 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.