IP INTELLIGENCE BRIEFING: 167.99.216.83/32
Classification: Moderate Risk Infrastructure
Date of Analysis: 2026-07-30
---
EXECUTIVE SUMMARY
IP address 167.99.216.83 is a cloud infrastructure endpoint owned by DigitalOcean, LLC operating from Amsterdam, Netherlands. The IP carries a moderate risk score of 50/100 with no active threat indicators. No open services were detected, and the IP is currently firewalled. This endpoint represents low-to-moderate risk cloud hosting infrastructure.
---
OWNERSHIP & INFRASTRUCTURE
| Attribute | Value |
|---|---|
| **Organization** | DigitalOcean, LLC |
| **ASN** | 14061 |
| **Network** | DIGITALOCEAN-167-99-0-0 (167.99.0.0/16) |
| **Location** | Amsterdam, North Holland, NL |
| **Infrastructure Type** | CloudCompute |
| **Classification** | Cloud-hosted, No Services |
---
THREAT ASSESSMENT
Risk Score: 50/100 (Moderate)
Threat Indicators:
- Blacklist Count: 0
- DNSBL Listed: 2 of 8 total lists
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Active Campaigns: None
Service Exposure: No open ports detected. The endpoint is classified as "Firewalled / No Services," indicating defensive network posture.
---
OBSERVATION HISTORY (15 Records)
Analysis of signal history reveals:
- Recent Activity: Observations concentrated on 2026-07-30
- Geolocation Signals: Mixed signals showing US coordinates (39.83, -98.58) with 2500km accuracy radius
- Operator Score: 0.15 (Minimal threat operator)
- Overall Confidence: 0.2667 (Low confidence due to sparse data)
- Threat Persistence: 0 days
- Persistent Malicious Activity: Not detected
---
NETWORK RELATIONSHIPS
Direct Relationships: 4 records, all indicating same-network associations with DIGITALOCEAN-167-99-0-0. No external entity relationships detected (hostnames, organizations, certificates).
Subnet Analysis (167.99.216.0/24):
- Neighbors: 1 active IP (167.99.216.171)
- Abuse Density: 0 (No abusive activity in neighborhood)
- Risk Distribution: 0 high, 0 medium, 0 low risk neighbors
---
RECOMMENDED ACTIONS
Based on risk assessment, the following firewall rules are recommended for defense-in-depth:
iptables:
```bash
iptables -A INPUT -s 167.99.216.83 -j DROP
```
nftables:
```bash
nft add rule inet filter input ip saddr 167.99.216.83 drop
```
nginx:
```nginx
deny 167.99.216.83;
```
pfSense:
```
167.99.216.83/32
```
---
INTELLIGENCE NARRATIVE
The target IP 167.99.216.83 operates as a DigitalOcean cloud infrastructure endpoint with moderate risk classification. The IP shows no evidence of active malicious behavior, with zero blacklist entries and no detected open services. The absence of threat indicators suggests this endpoint serves legitimate cloud hosting purposes.
The single neighbor IP (167.99.216.171) in the /24 subnet carries no risk score data and contributes to a zero abuse density rating for the subnet. This indicates the /24 block maintains a clean reputation profile.
Risk Context: The moderate risk score (50/100) is primarily attributed to operator scoring mechanisms rather than active threat activity. Given the cloud hosting context and lack of service exposure, the endpoint represents acceptable risk for defensive monitoring rather than immediate blocking.
Monitoring Recommendation: Continue observation with standard threat intelligence feeds. No immediate mitigation required unless new threat indicators emerge.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-167-99-0-0 |
| CIDR Block | 167.99.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 23% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 22:49:46 UTC |
| Last Seen | 2026-08-13 00:09:49 UTC |
| Profile Built | 2026-08-13 00:19:39 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 18 |
Full dossier details are available via our API.