# IP Intelligence Briefing: 161.35.43.18
Classification: Moderate Risk | Status: Cloud Infrastructure
## Executive Summary
IP 161.35.43.18 operates as a DigitalOcean cloud hosting environment in London, United Kingdom. The IP carries a moderate risk score of 60, primarily driven by cloud hosting reputation factors rather than direct malicious activity. The address resolves to a standard web server configuration with no immediate threat indicators in the neighborhood context.
## Technical Profile
- Organization: DigitalOcean, LLC (ASN: 14061)
- Network Block: 161.35.0.0/16 (DIGITALOCEAN-161-35-0-0)
- Location: London, England, GB
- Infrastructure Type: Cloud Compute
- Services: HTTP/2 (port 80), HTTPS (port 443)
- Server Fingerprint: Apache/2.4.37 (Rocky Linux) OpenSSL/1.1.1k
## Risk Assessment
The IP scored 60 on the risk scale, classified as "Moderate Risk." Contributing factors include:
- Cloud hosting infrastructure classification
- External threat feed association (Alienvault OTX flagged with `has_threats: true`)
- Standard commercial web server configuration
No direct threat indicators detected:
- Not a known attacker or spam source
- Not a Tor exit node or proxy
- No blacklist listings
- Zero abuse confidence score
## Observational History
Analysis of 20 recent observations reveals:
- Consistent cloud hosting classification over the observation period
- Geolocation signals from London, GB with threat indicators
- HTTP fingerprinting shows WordPress-related robots.txt configuration with admin disallow rules
- TLS certificate issued by Let's Encrypt for domain `vx0kchrymh8.c.updraftclone.com`
- Response time: 598ms average TTFB
- HTTP/2 enabled, HSTS not present
## Network Context
- Subnet Analysis: /24 block (161.35.43.0/24)
- Abuse Density: 0 (clean classification)
- Neighbor IPs: None detected in immediate subnet
- Threat Siblings: 0
## Relationship Graph
No external entity relationships detected beyond same-network associations with DIGITALOCEAN-161-35-0-0.
## SOC Action Recommendations
Based on the risk profile, the following actions are recommended:
1. Monitor but Do Not Block: The IP shows moderate risk primarily from hosting classification rather than active malicious behavior.
2. Traffic Inspection: If traffic from this IP reaches endpoints, inspect for:
- Unusual data exfiltration patterns
- Connection to known malicious domains
- Port 80/443 traffic anomalies
3. Certificate Monitoring: The TLS certificate points to `updraftclone.com` subdomain โ monitor for domain reputation changes.
4. Baseline Comparison: No immediate action required; treat as standard cloud hosting traffic.
Verdict: This IP represents a commercial cloud hosting endpoint with elevated risk classification due to infrastructure type rather than confirmed malicious activity. Continue monitoring and apply standard cloud traffic handling procedures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
| Honeypot | Trap endpoint probes | 1 |
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-161-35-0-0 |
| CIDR Block | 161.35.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Apache/2.4.37 (Rocky Linux) OpenSSL/1.1.1k |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | vx0kchrymh8.c.updraftclone.com |
| Valid From | 2026-07-30T11:28:52+00:00 |
| Valid Until | 2026-10-28T11:28:51+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 067090FDB3FD58DAA55523DE45EE79C4BCCD |
| Thumbprint | 8FB6DB6B87099597FF210A63C066C7D83D7D7E5C |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 21% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 32% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 30% | 2 | 3 |
| Overall | 23% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 05:12:43 UTC |
| Last Seen | 2026-08-12 21:21:31 UTC |
| Profile Built | 2026-08-12 21:30:04 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.