# Intelligence Briefing: 167.71.190.221/32
Classification: LOW RISK
Date: 2026-06-21
Provider: DigitalOcean, LLC (ASN 14061)
## Executive Summary
IP address 167.71.190.221 operates within the DIGITALOCEAN-167-71-0-0 network (167.71.0.0/16) as a cloud infrastructure host. The IP maintains a low-risk profile with a risk score of 25 and shows no active threat indicators. No firewall rules were recommended for blocking or filtering at this time.
## Profile Overview
Risk Assessment: The IP registered a risk score of 25, categorized as "Low Risk." Provider and authority scores were null, indicating minimal threat attribution. The IP is classified as a cloud compute host (Infrastructure Type: CloudCompute) with service purpose identified as "Single-Service Host."
Network Classification: The address operates on DigitalOcean infrastructure (ASN 14061). Control plane analysis identified the IP as stable with route changes of zero over the past 30 days. RPKI state and IRR consistency data were unavailable. DNSSEC validation was confirmed as valid.
Geolocation: The IP resolved to Clifton, New Jersey, United States. Geolocation consensus was validated across multiple sources, though geo-validation flags indicated implausibility with a 5,967 km distance discrepancy and 20ms RTT against a minimum possible 119.4ms threshold for that distance.
DNS Resolution: Forward DNS resolution confirmed the hostname "southnode.netcluescloud.com." Email authentication records (SPF, DMARC) were present for the associated domain.
## Threat Indicators
No active threat indicators were detected. The IP was not identified as:
- A Tor exit node
- A known attacker
- A spam source
- Listed on any blacklists (count: 0)
Campaign correlation analysis returned no matches, with zero correlated IPs and zero certificate matches.
## Historical Observation Analysis
Observation history contains 24 signals across multiple signal types. The most recent observations occurred on 2026-06-21. Analysis confirmed:
- No persistent malicious activity
- No ownership changes
- No threat persistence
Signal types included network classification (cloud infrastructure), subnet abuse density monitoring, and geolocation inference.
## Infrastructure and Relationships
The IP maintains 33 relationship entries, including:
- DNS associations with southnode.netcluescloud.com
- Network associations within the DIGITALOCEAN-167-71-0-0 CIDR block
Open port scanning identified SSH (port 22/tcp) with banner "SSH-2.0-OpenSSH_7.4." No TLS certificates or HTTP services were detected.
## Neighborhood Analysis
The /24 subnet (167.71.190.221/24) showed an abuse density of 1 with classification "mostly_clean." One threat sibling was identified among active siblings.
## Recommended Actions
No specific security actions or firewall rules were generated based on the current risk profile. The IP presents minimal threat and does not require immediate blocking or filtering measures.
Monitoring Recommendation: Continue routine observation. The low-risk profile and clean threat indicators suggest standard monitoring is sufficient.
---
*Intelligence generated via IPDebrief platform. All data derived from observed network signals.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-167-71-0-0 |
| CIDR Block | 167.71.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | southnode.netcluescloud.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | southnode.netcluescloud.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_7.4 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 28% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-28 12:25:01 UTC |
| Last Seen | 2026-06-29 05:22:29 UTC |
| Profile Built | 2026-06-29 05:24:37 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 24 |
Full dossier details are available via our API.