# IP INTELLIGENCE BRIEFING: 167.172.90.163
Classification: Defensive Security Analysis | Date: [Current] | Risk Level: LOW
---
## Executive Summary
IP 167.172.90.163 is a low-risk cloud computing endpoint hosted on DigitalOcean infrastructure in Singapore. The IP exhibits standard web server characteristics with no active threat indicators. Historical observations show stable network classification with minimal malicious activity.
---
## Infrastructure Profile
Network Identity:
- IP Address: 167.172.90.163/32
- ASN: 14061 (DigitalOcean)
- Organization: DigitalOcean, Inc.
- Country/Region: Singapore (SG)
- CIDR Block: 167.172.80.0/20
- Infrastructure Type: Cloud Computing
Risk Metrics:
- Overall Risk Score: 25/100 (Low Risk)
- Provider Risk Score: 0
- Operator Score: 0.1304 (Minimal)
- DNSBL Listings: 1/8 lists
---
## Network Services & Exposed Ports
| Port | Protocol | Service | Status |
|---|---|---|---|
| 80 | TCP | HTTP | Open |
| 443 | TCP | HTTPS | Open |
| 22 | TCP | SSH | Open |
Server Fingerprint:
- Web Server: Apache (powered by Caddy)
- SSH Banner: SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16
- HTTP Version: 2.0
- Response Time: ~1,036ms
---
## Threat Intelligence Assessment
Active Threat Indicators:
- Known Attacker: False
- Tor Exit Node: False
- Spam Source: False
- Campaign Association: None detected
- Blacklist Count: 0 (active threat feeds)
Control Plane Analysis:
- Route Stability: False (0 route changes in 30 days)
- DNSSEC Valid: True
- RPKI State: Not assessed
- IRR Consistency: Not assessed
---
## Historical Observation Analysis
Observation Timeline: 20 data points collected (most recent: 2026-06-28)
Temporal Risk Trends:
- Threat Persistence Days: 0 (no persistent malicious activity)
- Ownership Changes: 0
- Is Persistently Malicious: False
Observed Signal Types:
1. Geolocation Signals: Consistently identified as Singapore-based (confidence: 0.35)
2. Network Classification: Repeatedly identified as DigitalOcean cloud infrastructure (confidence: 0.85)
3. Service Discovery: SSH and web services consistently detected
---
## Neighborhood Analysis
Subnet: 167.172.90.0/24
- Abuse Density: 1 (Low)
- Classification: Mostly Clean
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
---
## Relationship Graph
Network Associations: 22 relationships identified, all mapping to DigitalOcean network infrastructure. No cross-organizational or cross-network relationships detected.
---
## Recommended Security Actions
Firewall/Network Policy:
- Allow: Standard web traffic (HTTP/HTTPS) from trusted sources
- Monitor: SSH access (port 22) for unauthorized access attempts
- Block: No immediate blocking recommended; risk level is low
SOC Guidance:
- No immediate threat response required
- Standard monitoring protocols apply
- Investigate only if unusual traffic patterns observed
---
## Conclusion
IP 167.172.90.163 presents a low-risk profile consistent with legitimate cloud hosting infrastructure. No active threat indicators detected. Standard defensive monitoring recommended.
Analyst Notes: Historical data shows stable infrastructure classification with no escalation of threat signals over observation period.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | digitalocean |
| ASN | AS14061 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Caddy |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 22% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-17 21:14:28 UTC |
| Last Seen | 2026-06-28 05:45:11 UTC |
| Profile Built | 2026-06-28 23:49:57 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.