# IP Intelligence Briefing: 167.99.66.42/32
Date: 2026-06-16
Classification: MODERATE RISK (Score: 50)
Reporting Analyst: IPDebrief Intelligence Team
---
## Executive Summary
IP address 167.99.66.42 is a DigitalOcean cloud infrastructure endpoint classified as moderate risk. The IP operates as a single-service host with SSH access enabled, showing no active threat indicators despite elevated risk scoring. Neighborhood analysis indicates a clean subnet with minimal abuse density.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 50 (Moderate) |
| **Provider** | DigitalOcean, LLC (ASN 14061) |
| **Network Block** | 167.99.0.0/16 |
| **Infrastructure Type** | CloudCompute |
| **Service Purpose** | Single-Service Host |
| **Open Ports** | 22/TCP (SSH) |
---
## Threat Indicators
Current Status: No active threat indicators detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0
- Campaign Correlation: None
DNSBL Status: Listed on 2 of 8 monitored lists (max severity: high)
---
## Observation History
Total Observations: 15 signals captured over monitoring period
Recent Activity:
- 2026-06-16 20:59: SSH service probe detected (OpenSSH_9.6p1 Ubuntu-3ubuntu13.16)
- 2026-06-16 20:28: Subnet classification returned "clean" with 0 abuse density
- 2026-06-16 20:28: Geolocation data inconsistent (US coordinates vs. SG profile)
- 2026-06-16 20:26: Ownership stability confirmed (0 changes)
- 2026-06-16 20:25: DNSBL listings identified (2 high-severity)
Risk Trend: Stable with no persistent malicious behavior detected
---
## Network Relationships
Associated Entities:
- Same Network: DIGITALOCEAN-167-99-0-0 (primary network association)
No relationships detected for:
- Hostnames
- Organizations
- SSL Certificates
- Correlated IPs
---
## Neighborhood Analysis
Subnet: 167.99.66.42/24
| Metric | Value |
|---|---|
| **Abuse Density** | 0% |
| **Classification** | Clean |
| **Total Siblings** | 1 |
| **Active Siblings** | 0 |
| **Threat Siblings** | 0 |
Risk Distribution: High: 0, Medium: 0, Low: 0
---
## Recommended Actions
Risk-Based Recommendation: BLOCK
Firewall Implementation:
```bash
# iptables
iptables -A INPUT -s 167.99.66.42 -j DROP
# nftables
nft add rule inet filter input ip saddr 167.99.66.42 drop
# nginx
deny 167.99.66.42;
# pfSense
167.99.66.42/32
# Cloudflare WAF
{"description": "Block 167.99.66.42 β IPDebrief risk score 50", "action": "block"}
# AWS WAF
{"Addresses": ["167.99.66.42/32"], "Description": "IPDebrief risk 50"}
```
---
## Intelligence Notes
Key Observations:
1. The moderate risk score (50) appears driven by DNSBL listings rather than active exploitation attempts
2. Geolocation inconsistencies (SG vs US) may indicate misconfigured geo-database or legitimate cloud migration
3. Single open port (SSH 22) suggests minimal attack surface
4. Clean neighborhood classification indicates no lateral threat correlation
5. No correlation to known campaigns or malicious entities
Assessment: This IP warrants defensive blocking based on risk scoring and DNSBL presence, despite lack of immediate threat indicators. The DigitalOcean hosting environment presents a legitimate cloud infrastructure use case but requires standard cloud security posture validation.
Priority: MEDIUM
Action Required: Firewall rule deployment recommended pending SOC validation
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-167-99-0-0 |
| CIDR Block | 167.99.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 2 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 17% | 1 | 1 |
| Overall | 22% | 9 | 11 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-13 03:44:56 UTC |
| Last Seen | 2026-06-26 14:31:11 UTC |
| Profile Built | 2026-06-21 20:23:36 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 18 |
Full dossier details are available via our API.