# THREAT INTELLIGENCE BRIEFING
IP Address: 161.35.101.10/32
Date: Current Analysis Cycle
Classification: Cloud Infrastructure IP
---
## EXECUTIVE SUMMARY
IP address 161.35.101.10 is a DigitalOcean cloud compute infrastructure endpoint located in North Bergen, New Jersey, United States. The IP carries an overall risk score of 25 (Low Risk) and shows no active service exposure. However, the IP appears on one blacklist entry out of eight evaluated DNSBL feeds, indicating potential historical or contextual reputation concerns. No direct threat indicators or active malicious behavior were observed.
---
## INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| **ASN** | 14061 (DIGITALOCEAN-ASN) |
| **Organization** | DigitalOcean, LLC, US |
| **CIDR Block** | 161.35.96.0/20 |
| **Geolocation** | United States, New Jersey, North Bergen |
| **Infrastructure Type** | CloudCompute |
| **Hosting** | Enabled |
| **IPv6** | Not detected |
---
## NETWORK BEHAVIOR
Service Status: No active services detected
- Open Ports: None
- TLS Certificates: None
- HTTP Services: None
- DNS Resolution: Forward resolution failed
Network Behavior:
- PTR hostnames: Unresolved
- DNSSEC: Valid
- Reverse DNS: 10.101.35.161.in-addr.arpa (no RRSIG)
---
## THREAT INDICATORS
Reputation Signals:
- Risk Score: 25 (Low)
- Blacklist Status: Listed on 1 of 8 DNSBL feeds
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
Campaign Correlation: None identified
Control Plane:
- RPKI State: Not verified
- Route Stability: Unstable (0 route changes in 30 days)
- DNSBL Listing: 1 active listing
---
## OBSERVATION HISTORY
Total Observations: 11 signals across the monitoring period
Recent Activity (2026-07-29):
- Port scanning activity detected
- Geolocation inference: US (65% confidence, 2,500 km accuracy)
- ASN resolution confirmed: DigitalOcean (161.35.96.0/20)
- DNSSEC validation: Passed
---
## SUBNET ANALYSIS (161.35.101.0/24)
Neighborhood Risk Assessment:
- Total Siblings: 2 active IPs
- Abuse Density: 0%
- Risk Distribution: 2 medium-risk neighbors
Notable Neighbors:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 161.35.101.104 | 40 | 50 |
| 161.35.101.179 | 40 | 50 |
Subnet Classification: No inherited risk from neighborhood
---
## RELATIONSHIP GRAPH
No direct relationships identified with:
- Related subnets
- Hostnames
- Organizations
- SSL certificates
---
## TRAFFIC ANALYTICS
Traceroute Analysis:
- Hop Count: 15
- First Hop RTT: 0.1 ms
- Last Hop RTT: 18.9 ms
- Timeouts: 4 hops
- Transit Networks: Comcast, Cogent
---
## RECOMMENDED ACTIONS
Immediate Actions: No specific firewall rules generated based on current risk profile
Monitoring Recommendations:
1. Monitor the IP for service activation (port scanning activity was observed)
2. Watch for blacklist status changes on the single listed feed
3. Correlate with any 161.35.101.x subnet activity
4. Review the two medium-risk neighbors (161.35.101.104, 161.35.101.179) for context
Firewall Policy: Standard allow/deny based on organizational security policy. No blocking required at this time.
---
## INTELLIGENCE CONCLUSION
IP 161.35.101.10 represents a low-risk DigitalOcean cloud infrastructure endpoint with no active services and no current malicious behavior. The single blacklist listing appears historical or contextual rather than indicative of active abuse. However, recent port scanning activity and the presence of two medium-risk neighbors in the same /24 subnet warrant continued monitoring. No immediate blocking action is recommended, but maintain visibility on this IP in threat monitoring systems.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-161-35-0-0 |
| CIDR Block | 161.35.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 13% | 1 | 1 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 1 |
| geolocation | 19% | 1 | 2 |
| Overall | 19% | 8 | 10 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-23 20:05:10 UTC |
| Last Seen | 2026-08-12 17:55:40 UTC |
| Profile Built | 2026-08-12 18:05:32 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 20 |
Full dossier details are available via our API.