## IP Intelligence Briefing: 167.99.147.201
Classification: Low Risk - Cloud Infrastructure Host
Date: 2026-06-18
Intel Confidence: Moderate (21 historical observations)
---
Executive Summary
IP 167.99.147.201 is a DigitalOcean cloud compute instance with a risk score of 25/100 (Low Risk). The address shows persistent minimal risk characteristics over the observation period with no active threat indicators. One DNSBL listing detected; geographic validation flags require monitoring.
---
Risk Assessment
| Metric | Value | Status |
|---|---|---|
| Risk Score | 25 | Low Risk |
| Provider Score | 0 | N/A |
| Authority Score | 0 | N/A |
| Operator Score | 0.1304 | Minimal |
| DNSBL Listings | 1 of 8 | Minor Flag |
| Abuse Confidence | Not Available | Unknown |
---
Infrastructure Profile
- Organization: DigitalOcean, LLC (ASN 14061)
- Network Block: 167.99.144.0/20
- Location: US (North Bergen, NJ region)
- Infrastructure Type: CloudCompute / Hosting
- Service Purpose: Single-Service Host
- DNSSEC: Valid
- RTT Validation: Flagged - 21ms observed vs 119.3ms minimum possible for 5963km distance
---
Active Signals
- Open Ports: TCP/22 (SSH - OpenSSH 9.6p1 Ubuntu-3ubuntu13.16)
- TLS/HTTP: None detected
- Hosted Domains: 0
- Campaign Associations: None
- Tor Exit Node: No
---
Threat Indicators
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0
- Campaign Matches: 0
- Threat Persistence: 0 days
- Persistently Malicious: No
---
Neighborhood Analysis
| Metric | Value |
|---|---|
| Subnet | 167.99.147.201/24 |
| Abuse Density | 1 |
| Classification | Mostly Clean |
| Total Siblings | 1 |
| Active Siblings | 1 |
| Threat Siblings | 1 |
---
Historical Trend (Last 21 Observations)
- Risk Profile: Stable - Consistent "Minimal" operator score (0.1304) across all observations
- Latest Signals: 2026-06-18
- Geolocation Signals: 2026-06-13 (US country inference)
- Threat Trend: No degradation; single threat observation detected
---
Network Relationships
- 26 network-level relationships identified
- All target: DIGITALOCEAN-167-99-0-0
- No hostname or certificate associations detected
---
Recommended Actions
1. Monitor: DNSBL listing warrants continued monitoring; 1 of 8 lists
2. Allow: No immediate blocking recommended for low-risk cloud infrastructure
3. Verify: Geographic validation discrepancy suggests potential misconfiguration or routing anomaly
4. Correlate: One threat sibling detected in /24 subnet - cross-reference for potential lateral movement
---
Firewall Rule Recommendation
No specific firewall rules generated (risk score < 50 threshold). Standard egress/ingress policies apply.
---
Analyst Notes: This IP represents legitimate cloud infrastructure with acceptable risk characteristics. Monitor for changes in DNSBL status and the threat sibling activity in the adjacent subnet.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | β |
| CIDR Block | 167.99.144.0/20 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 42% | 2 | 5 |
| routing | 32% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 28% | 3 | 4 |
| reputation | 27% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 29% | 12 | 20 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:52 UTC |
| Last Seen | 2026-06-27 01:39:44 UTC |
| Profile Built | 2026-06-27 23:13:27 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 29 |
Full dossier details are available via our API.