IPDebrief

162.243.220.84

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# Intelligence Briefing: 162.243.220.84/32

Date: August 5, 2026

Classification: High Risk

Intel Source: IPDebrief Intelligence Platform

---

## Executive Summary

IP address 162.243.220.84 is a DigitalOcean cloud compute infrastructure endpoint located in New York, US, assigned a high-risk reputation score of 70. The IP resolves to mail.thelegalassistant.com and exhibits DNS blacklist listings across 4 of 8 total threat feeds. While the IP itself shows no active threat indicators or open services, the elevated risk score warrants monitoring due to DNSBL presence and route instability.

---

## Network Ownership & Infrastructure

AttributeValue
**Organization**DigitalOcean, LLC
**ASN**AS14061
**Network Block**162.243.0.0/16
**CIDR Block**162.243.220.84/32
**Geolocation**New York, NY, US
**Infrastructure Type**CloudCompute
**ISP Classification**Cloud Hosting

---

## Threat Assessment

Risk Indicators

Control Plane Analysis

---

## DNS & Email Analysis

FieldValue
**PTR Hostname**mail.thelegalassistant.com
**Forward Resolution**Confirmed
**SPF Record**Present
**DMARC Record**Present
**TXT Record Count**0

Email authentication mechanisms are properly configured, reducing likelihood of spoofing abuse from this endpoint.

---

## Observation History Analysis

Total Observations: 22

Data Period: Recent 30-day window

Key Historical Signals:

1. 2026-08-05 17:47:15 – Basic operator classification with score 0.2609

2. 2026-08-05 17:48:30 – Subnet abuse density assessment (mostly_clean classification)

3. 2026-08-05 17:48:57 – ASN and geolocation confirmation (AS14061, New York)

4. 2026-07-29 18:33:51 – Traceroute completion (15 hops, target reached)

No persistent malicious behavior observed. Threat observation count: 1.

---

## Network Neighborhood Analysis

Subnet: 162.243.220.0/24

Abuse Density: Low

Total Siblings: 1

Active Siblings: 1

Threat Siblings: 1

The /24 subnet shows minimal abuse activity with only one threat-identified sibling IP.

---

## Relationship Graph

Total Relationships: 15

Relationship Types:

All relationships confirm consistent ownership and DNS configuration.

---

## Recommended Actions

For SOC Analysts:

1. Monitor – Continue passive monitoring for any behavioral changes

2. Block if Necessary – Consider firewall rules if DNSBL listings are confirmed malicious

3. Verify Legitimacy – Confirm mail.thelegalassistant.com is legitimate and not compromised

Recommended Firewall Rules (iptables):

```

# Block if risk profile warrants

iptables -A INPUT -s 162.243.220.84 -j DROP

```

Cloudflare WAF Rule (if applicable):

```

IP 162.243.220.84 β†’ Block

```

---

## Conclusion

IP 162.243.220.84 presents elevated risk due to DNSBL listings and route instability, though no active threat indicators or open services were detected. The endpoint is properly configured for email delivery with SPF/DMARC. SOC teams should monitor for behavioral changes and verify the legitimacy of the associated domain before implementing blocking measures.

Priority Level: Medium

Recommended Action: Monitor with alerts for DNSBL updates and threat activity

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionNew Jersey
CitySecaucus
Timezoneβ€”
Latitude40.79
Longitude-74.06

🏒 Ownership & Registration

OrganizationDigitalOcean, LLC
ASNAS14061
Network NameDIGITALOCEAN-162-243-0-0
CIDR Block162.243.0.0/16
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRmail.thelegalassistant.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesmail.thelegalassistant.com

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 β€” Basic operator with some routing infrastructure
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
40%
25
routing
13%
11
services
19%
22
ownership
27%
23
reputation
26%
13
geolocation
42%
23
Overall28%1017
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-23 13:56:22 UTC
Last Seen2026-08-12 17:40:55 UTC
Profile Built2026-08-12 17:49:01 UTC
Data FreshnessLive
Signal Types24
Total Observations25
πŸ” 24 signal types Β· 25 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.