# IP Intelligence Briefing: 168.144.101.237/32
## Executive Summary
Target IP 168.144.101.237 is a DigitalOcean cloud infrastructure address located in Singapore with a moderate risk score of 50. No active threat indicators or malicious activity observed. Network environment shows minimal abuse density with one low-risk sibling IP in the /24 subnet.
## Infrastructure Profile
- Owner/Provider: DigitalOcean, LLC (ASN 14061)
- Geolocation: Singapore (1.35, 103.82), timezone Asia/Singapore
- Infrastructure Type: CloudCompute (is_cloud: true)
- Network Classification: Firewalled / No Services
- CIDR Block: 168.144.96.0/20 (BGP prefix origin)
- Route Stability: Stable (route_changes_30d: 0, is_route_stable: true)
## Threat Assessment
- Overall Risk Score: 50 (Moderate Risk)
- Abuse Confidence: No active abuse indicators detected
- Blacklist Status: Clean (0 blacklist hits across 8 DNSBL checks)
- Threat Indicators: None
- Campaign Activity: No known campaign associations
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
Control Plane: BGP origin 6939 14061, RPKI state valid, IRR consistency match, route stable for 4,984 days
## Network Neighborhood Analysis
Subnet: 168.144.101.237/24
- Abuse Density: 0.5 (low-moderate)
- Classification: mostly_clean
- Total Siblings: 2
- Active Siblings: 0
- Threat Siblings: 1
Neighbor IPs:
- 168.144.101.23: Risk Score 25 (low), Authority Score 50
## Observation History
- Total Observations: 26 signal events
- Recent Classification: Consistently identified as cloud infrastructure (DigitalOcean)
- Geolocation Consistency: Singapore across all observations
- Threat Persistence: 0 days (not persistently malicious)
- Ownership Changes: None detected
## Network Relationships
- 29 Relationship Links: All classified as "Same Network" (NET-168-144-0-0-1)
- Network Association: Confirmed DigitalOcean infrastructure network membership
## Security Actions & Recommendations
Current Status: No active firewall rules required. The IP presents as a standard cloud infrastructure address with no observed malicious behavior.
Recommended Monitoring:
- Monitor for service enumeration (current: firewalled/no services)
- Watch for DNS resolution activity (currently: no PTR hostnames)
- Track neighborhood abuse density changes
## Intelligence Narrative
The target IP 168.144.101.237 operates as DigitalOcean cloud infrastructure in Singapore. Historical data (26 observations) confirms consistent cloud provider classification with no escalation in risk posture. The /24 subnet exhibits low abuse density (0.5) with one low-risk neighbor IP. Control plane data shows stable BGP routing and valid RPKI state. No threat indicators, blacklist entries, or known campaign associations detected. The moderate risk score of 50 reflects the inherent risk of cloud hosting infrastructure rather than malicious activity. Current service posture indicates the IP is firewalled with no active services exposed.
Classification: LOW THREAT - Standard cloud infrastructure, no malicious indicators
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
| Enumeration | Path/resource enumeration | 4 |
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | β |
| CIDR Block | 168.144.96.0/20 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| 8080 | http-alt | tcp | β |
| Closed Ports | 25, 80, 443, 3389, 8443 (2 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 19% | 3 | 4 |
| services | 21% | 2 | 2 |
| ownership | 22% | 3 | 4 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 25% | 13 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (65%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-19 00:43:41 UTC |
| Last Seen | 2026-06-28 08:09:43 UTC |
| Profile Built | 2026-06-29 02:14:40 UTC |
| Data Freshness | Live |
| Signal Types | 28 |
| Total Observations | 31 |
Full dossier details are available via our API.