# IP Intelligence Briefing: 167.172.168.149/32
## Executive Summary
IP address 167.172.168.149 is a DigitalOcean cloud infrastructure endpoint located in Frankfurt am Main, Germany (ASN 14061). The IP presents a low-risk profile with a risk score of 25, classified as "Low Risk" by the threat intelligence system. No active threat indicators, blacklisting, or malicious campaigns were detected.
---
## Risk Assessment
- Overall Risk Score: 25 (Low Risk)
- Reputation Classification: Low Risk
- Abuse Confidence Score: Not applicable
- Is Known Attacker: No
- Is Spam Source: No
- Is Tor Exit Node: No
- Is Proxy: No
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **Organization** | DigitalOcean |
| **ASN** | 14061 |
| **Country** | DE (Germany) |
| **City** | Frankfurt am Main |
| **Infrastructure Type** | Cloud Compute |
| **Network Classification** | Cloud/Hosting |
| **BGP Prefix** | 167.172.160.0/20 |
---
## Network Activity
- Open Ports: None (firewalled/no services)
- HTTP Services: None detected (404 status code)
- SSL/TLS Certificates: None
- PTR Resolution: None
- Hosted Domains: None
- Email Authentication: No SPF/DMARC records
---
## Threat Indicators
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 total lists (minimal impact)
- Known Campaigns: None
- Threat Feeds: No matches
- Pulsedive Risk: Not available
---
## Neighborhood Analysis (167.172.168.0/24)
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
- Abuse Density: 1
- Classification: Mostly Clean
- Inherited Risk: 2
The /24 subnet shows minimal activity with only one active sibling IP. The abuse density metric is low, indicating limited malicious activity in the neighborhood.
---
## Relationship Graph
The IP shows consistent relationships with DigitalOcean infrastructure networks (22 relationship entries). All relationships indicate network-level connectivity to DigitalOcean services without malicious associations.
---
## Historical Observations (25 observations analyzed)
Recent signal history shows consistent low-risk classification:
- June 18, 2026: Minimal operator score (0.1304), low confidence (0.25-0.30)
- June 17, 2026: Consistent signal patterns with 6 dimension coverage
- June 13, 2026: Port scanning detected with no open services identified
Temporal analysis indicates no persistent malicious behavior (0 threat persistence days, 0 ownership changes).
---
## Recommended Security Actions
Based on the risk profile, the following actions are recommended:
1. No immediate blocking required โ IP classified as low risk
2. Monitor for service changes โ Currently firewalled with no open ports
3. Standard logging โ Include in normal traffic monitoring
4. No firewall rules needed โ No specific iptables/nftables rules recommended
Note: This IP operates in a legitimate cloud hosting environment (DigitalOcean). If observed in suspicious contexts, correlate with additional intelligence before taking action.
---
## Conclusion
IP 167.172.168.149 represents a benign DigitalOcean cloud infrastructure endpoint. The low risk score, lack of threat indicators, and consistent historical observations support continued monitoring without restrictive measures. No immediate security intervention is warranted.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | digitalocean |
| ASN | AS14061 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | nginx/1.22.0 |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 20% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 24% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 22% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:52 UTC |
| Last Seen | 2026-06-27 01:33:32 UTC |
| Profile Built | 2026-06-27 23:59:05 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 29 |
Full dossier details are available via our API.