# IP Intelligence Briefing: 167.172.77.62
## Executive Summary
IP 167.172.77.62 is a Low Risk (Risk Score: 30/100) web server endpoint hosted on DigitalOcean cloud infrastructure in Singapore. The IP demonstrates stable operational characteristics with no active malicious indicators, though the /24 neighborhood shows minor abuse activity that warrants contextual awareness.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **IP Address** | 167.172.77.62/32 |
| **Organization** | DigitalOcean (ASN: 14061) |
| **Location** | Singapore (SG) |
| **CIDR Block** | 167.172.0.0/16 |
| **Network Type** | Cloud Infrastructure |
| **Classification** | Web Server |
## Service Footprint
The IP hosts standard web server services with the following open ports:
- Port 80/tcp: HTTP
- Port 443/tcp: HTTPS
- Port 22/tcp: SSH (OpenSSH 9.6p1 Ubuntu)
- Port 8080/tcp: HTTP-alt
TLS Configuration: The endpoint presents a Let's Encrypt certificate for `crmsaudi.dev` with SANs covering `*.crmsaudi.dev` and `crmsaudi.dev`. Server fingerprint identifies nginx/1.24.0 on Ubuntu. Security headers include HSTS (31536000s), CSP (default-src 'self'), and HTTP/2 support.
## Threat Assessment
- Overall Risk: Low Risk (Score: 30)
- Known Threats: None
- Blacklist Status: Listed on 1 of 8 DNSBL checks (minor concern)
- Campaign Activity: No correlation with known malicious campaigns
- Tor/Proxy/VPN: Negative indicators
- Abuse Confidence: Not available
## Operational History
Analysis of 25 observation signals reveals consistent operational patterns:
- Ownership remains stable with zero changes
- No persistent malicious behavior detected
- Recent observations (June 2026) show stable configuration
- Security headers (CSP, HSTS, Referrer-Policy) present and properly configured
- Average response time: ~237ms
## Network Neighborhood
The /24 subnet (167.172.77.0/24) shows:
- Abuse Density: 1 (low)
- Classification: Mostly Clean
- Active Siblings: 1
- Threat Siblings: 1
The presence of one threat sibling in the neighborhood suggests localized abuse activity, though the target IP itself maintains a clean threat profile.
## Security Actions
No specific firewall rules or mitigation recommendations are required at this time. The IP's low risk score and absence of active threat indicators support continued monitoring without immediate blocking actions.
## Intelligence Conclusion
IP 167.172.77.62 operates as a legitimate web hosting endpoint on DigitalOcean infrastructure. The endpoint hosts what appears to be a development or test environment (`crmsaudi.dev`). While the immediate threat profile is low, SOC analysts should maintain awareness of the neighborhood's abuse density and monitor for any changes in the threat sibling activity. No immediate defensive actions are warranted.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | digitalocean |
| ASN | AS14061 |
| Network Name | DigitalOcean |
| CIDR Block | 167.172.0.0/16 |
| RIR | ARIN |
| Country | US |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| 8080 | http-alt | tcp | β |
| Closed Ports | 25, 3389, 8443 (4 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | *.crmsaudi.devcrmsaudi.dev |
| Valid From | 2026-05-11T09:15:59+00:00 |
| Valid Until | 2026-08-09T09:15:58+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 05A3428685CBB466F538AB3B232C3C46E585 |
| Thumbprint | 6710F2B10361E8E8196F66A6F5E3D22511341389 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 40% | 2 | 3 |
| Overall | 26% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-26 06:50:20 UTC |
| Last Seen | 2026-06-29 02:45:43 UTC |
| Profile Built | 2026-06-29 08:48:14 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.