IPDebrief

162.243.114.126

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 162.243.114.126

Classification: Cloud Infrastructure / Low Risk with Neighborhood Contamination

Report Date: 2026-06-28

Risk Score: 25/100 (Low Risk)

---

## Executive Summary

IP address 162.243.114.126 is a DigitalOcean cloud infrastructure endpoint hosting web services. While the IP itself presents low-risk characteristics (risk score 25), the associated /24 subnet exhibits elevated abuse density (1.0) with one high-risk neighbor (162.243.114.171, risk score 80). The target hosts a South African-registered domain (do2.weexcel.co.za) on outdated Apache server software, presenting moderate vulnerability concerns. No active malicious campaigns detected.

---

## Network Infrastructure

AttributeValue
**Organization**DigitalOcean, LLC
**ASN**14061
**Location**Secaucus, NJ, US
**Infrastructure Type**Cloud Compute / Web Server
**CIDR Block**162.243.0.0/17
**BGP Prefix**162.243.0.0/17 (Unstable routing)

---

## Service Analysis

Open Ports:

Server Fingerprint:

TLS Certificate Analysis:

DNS Resolution:

---

## Threat Indicators

IndicatorStatus
**Risk Score**25 (Low)
**DNS Blacklist**1 of 8 lists
**Tor Exit Node**No
**Known Attacker**No
**Spam Source**No
**Abuse Confidence**Not applicable
**Known Campaigns**None

Control Plane Assessment:

---

## Neighborhood Analysis

Subnet: 162.243.114.126/24

High-Risk Neighbor Identified:

Assessment: The target IP shares a subnet with confirmed malicious activity. While the target maintains a low individual risk score, the neighborhood contamination suggests potential lateral threat vectors or shared infrastructure risk.

---

## Historical Observations

Total Observations: 22

Recent Activity Timeline:

Geolocation Discrepancy:

Assessment: Geolocation data shows significant inconsistency, suggesting the IP may be routed through multiple points or the inference models are unreliable.

---

## Relationship Graph

Total Relationships: 63

Primary Associations:

---

## Recommended Actions

Immediate:

Firewall Configuration:

Vulnerability Mitigation:

---

## Threat Intelligence Conclusion

IP 162.243.114.126 represents a low-risk cloud infrastructure endpoint with moderate infrastructure concerns. The primary intelligence value lies in neighborhood association with confirmed malicious activity (162.243.114.171, risk score 80). While the target IP itself shows no direct malicious indicators, SOC analysts should:

1. Monitor for lateral movement or shared infrastructure compromise

2. Verify TLS certificate legitimacy

3. Consider blocking high-risk neighbor if within organizational scope

4. Track any changes in DNS blacklist status or neighborhood abuse density

Confidence Level: Moderate

Campaign Association: None detected

Recommended Priority: Monitor

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionNY
CityNew York
Timezoneβ€”
Latitude40.79
Longitude-74.06

🏒 Ownership & Registration

OrganizationDigitalOcean, LLC
ASNAS14061
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRdo2.weexcel.co.za
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesdo2.weexcel.co.za

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPF1/2 domains
DMARC1/2 domains
FCrDNSVerified
DNSSECValid
CAANot configured
Domains Checked2 domains

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
Closed Ports22, 25, 3389, 8080, 8443 (2 open / 7 scanned)
ServerApache/2.2.27 (Unix) mod_ssl/2.2.27 OpenSSL/1.0.1e-fips mod_bwlimited/1.4 PHP/5.3.28
HTTP Titleβ€”

πŸ” TLS Certificate

A self-signed certificate was detected. This is common for development servers, internal services, or IoT devices.
⚠️
CN=tmp-ade573.xyz
Issued by CN=tmp-ade573.xyz
Self-signed: Yes
SANstmp-ade573.xyzmail.tmp-ade573.xyzwww.tmp-ade573.xyzwebdisk.tmp-ade573.xyzwebmail.tmp-ade573.xyzcpanel.tmp-ade573.xyzautodiscover.tmp-ade573.xyzwhm.tmp-ade573.xyz
Valid From2026-05-03T23:47:30+00:00
Valid Until2027-05-03T23:47:30+00:00
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period365 days
Serial Number41877954
Thumbprint0EB893E8FAB9513766C52DB8EE840D6F8B5F690D

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
26%
24
routing
8%
11
services
26%
23
ownership
20%
23
reputation
28%
13
geolocation
33%
23
Overall24%1017
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-15 20:46:57 UTC
Last Seen2026-06-28 02:45:09 UTC
Profile Built2026-06-28 20:49:14 UTC
Data FreshnessLive
Signal Types23
Total Observations28
πŸ” 23 signal types Β· 28 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.