IPDebrief

167.71.175.236

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target: 167.71.175.236/32

Classification: Cloud Infrastructure Endpoint

Risk Level: Moderate Risk (Score: 50/100)

Report Generated: 2026-06-18

---

## EXECUTIVE SUMMARY

The IP address 167.71.175.236 is a DigitalOcean cloud compute instance operating from New Jersey, US. The endpoint demonstrates moderate risk characteristics with active DNSBL listings and associated hostname infrastructure. The IP resolves to a scan infrastructure domain (leakix.org) and maintains minimal threat indicators within its /24 neighborhood.

---

## OWNERSHIP AND INFRASTRUCTURE

---

## NETWORK SERVICES AND FINGERPRINTING

The endpoint operates standard web and administrative services:

---

## DNS AND RESOLUTION PROFILE

---

## THREAT INDICATORS

---

## OBSERVATION HISTORY

The IP generated 25 historical observations with the following temporal patterns:

- DNSBL listings detected with high severity on 2026-06-18T23:32:01 UTC (1 of 8 lists)

- Operator score remained consistent at 0.2609 across multiple observations

- Geolocation signals consistently reported US with 35-60% confidence

---

## NETWORK RELATIONSHIPS

---

## NEIGHBORHOOD ANALYSIS

Subnet: 167.71.175.236/24

---

## SECURITY ACTIONS AND RECOMMENDATIONS

Based on the risk profile, the following defensive measures are recommended:

1. DNSBL Monitoring: The IP is listed on 2 DNSBL feeds with 8 total associations. Monitor for escalation to additional blacklists.

2. SSH Access: Port 22 is open with Debian 11 OpenSSH. Implement rate limiting and consider key-based authentication only.

3. Hostname Association: The reverse DNS resolves to a scan infrastructure domain (leakix.org). Verify this is intentional operational infrastructure.

4. Cloud Egress Filtering: As a DigitalOcean cloud instance, implement appropriate egress controls if the endpoint should not communicate externally.

5. Route Stability: The IP is not flagged for route stability. Monitor for any BGP or routing anomalies that could indicate infrastructure manipulation.

---

## RISK ASSESSMENT

The IP address demonstrates moderate risk primarily due to:

However, the endpoint lacks:

Recommended Action: Monitor with standard SOC procedures; no immediate blocking recommended absent additional threat indicators.

---

END OF BRIEFING

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionNJ
CityClifton
Timezoneβ€”
Latitude40.84
Longitude-74.14

🏒 Ownership & Registration

OrganizationDigitalOcean, LLC
ASNAS14061
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRca7e79b6df.scan.leakix.org
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesca7e79b6df.scan.leakix.org

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeMulti-Service Host
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
22sshtcp
Closed Ports25, 443, 3389, 8080, 8443 (2 open / 7 scanned)
Serverlighttpd/1.4.59
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_8.4p1 Debian-5+deb11u7

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
28%
24
routing
8%
11
services
28%
23
ownership
20%
23
reputation
27%
13
geolocation
23%
22
Overall22%1016
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-07 23:03:52 UTC
Last Seen2026-06-27 01:35:42 UTC
Profile Built2026-06-27 23:43:08 UTC
Data FreshnessLive
Signal Types23
Total Observations30
πŸ” 23 signal types Β· 30 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.