# IP Intelligence Briefing: 167.172.104.129
## Executive Summary
IP 167.172.104.129 is a DigitalOcean cloud computing instance located in Frankfurt am Main, Germany, classified as Low Risk (risk score: 25). The IP operates as a single-service host with SSH enabled and demonstrates no malicious indicators. No specific defensive actions are currently required.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **IP Address** | 167.172.104.129/32 |
| **Organization** | DigitalOcean (ASN 14061) |
| **Network** | 167.172.96.0/20 |
| **Location** | Frankfurt am Main, Hesse, Germany (DE) |
| **Infrastructure Type** | CloudCompute |
| **Reputation** | Low Risk |
| **Risk Score** | 25 (0-100 scale) |
Ownership & Registration:
- RIR: ARIN
- CIDR Block: 167.172.0.0/16
- Abuse Contact: Available via RDAP
- No ownership changes detected
---
## Network Services & Exposed Ports
Open Ports:
- Port 22 (TCP/SSH): OpenSSH_9.6p1 Ubuntu-3ubuntu13.18
DNS Analysis:
- No PTR hostnames
- No forward resolution
- Zero hosted domains
- No SPF/DMARC email authentication records
Control Plane:
- BGP Prefix: 167.172.96.0/20
- Origin ASN: 14061 (DigitalOcean)
- DNSSEC Valid: Yes
- DNSBL Listed: 1 of 8 total lists (minimal operator score: 0.1304)
---
## Threat Intelligence Indicators
Threat Classification:
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Proxy/VPN: No
- CDN: No
Abuse Signals:
- Blacklist Count: 0
- Abuse Confidence Score: Not applicable
- Pulsedive Risk: Not reported
- Known Campaigns: None
Temporal Analysis:
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Is Persistently Malicious: No
---
## Neighborhood Analysis
Subnet: 167.172.104.129/24
- Classification: Clean
- Abuse Density: 0%
- Total Siblings: 2
- Active Siblings: 2
- Threat Siblings: 0
Neighbor IP Assessment:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 167.172.104.91 | 40 | 50 |
The immediate /24 subnet shows minimal threat activity with only one sibling IP (167.172.104.91) exhibiting elevated risk (score 40). The target IP remains isolated from active threat neighbors.
---
## Observation History
Total Observations: 17 signals collected
Recent Activity: No significant threat patterns observed
Key Historical Signals:
- 2026-07-30 23:56:12: Subnet classified as "clean" (abuse density: 0, inherited risk: 0)
- 2026-07-30 23:52:08: SSH service detected (OpenSSH 9.6p1 Ubuntu-3ubuntu13.18)
- 2026-07-30 23:49:37: Operator score: 0.1304 (Minimal)
No escalation in risk signals over the observation window. The IP maintains consistent classification as a legitimate cloud infrastructure asset.
---
## Relationship Graph
All detected relationships map to the DigitalOcean network infrastructure. No associated hostnames, organizations, or SSL certificates were identified beyond the provider network designation.
---
## Recommended Actions
Current Risk Profile: LOW RISK
Recommended Actions: None
Firewall Rules: Not recommended at this time
Monitoring Guidance:
- Standard logging applicable
- No specific block/allow rules required
- Continue baseline monitoring for any risk score changes
---
## SOC Analyst Notes
This IP represents a standard DigitalOcean cloud hosting environment with no malicious indicators. The single open SSH port is consistent with typical cloud infrastructure configurations. The neighbor IP 167.172.104.91 (risk score 40) may warrant separate investigation if it appears in threat intelligence feeds, but it does not currently impact the threat posture of the target IP.
No immediate defensive action required. Include in baseline monitoring only if contextual correlation with other threat indicators occurs.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | digitalocean |
| ASN | AS14061 |
| Network Name | DigitalOcean |
| CIDR Block | 167.172.0.0/16 |
| RIR | ARIN |
| Country | US |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 21% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 22:49:46 UTC |
| Last Seen | 2026-08-13 00:09:09 UTC |
| Profile Built | 2026-08-13 00:19:39 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 19 |
Full dossier details are available via our API.