## INTELLIGENCE BRIEFING: 168.144.95.207/32
Classification: Low Risk / Cloud Infrastructure
Date: 2026-06-28
Analyst: IPDebrief Intelligence
---
EXECUTIVE SUMMARY
IP 168.144.95.207 is a DigitalOcean cloud compute instance (ASN 14061) operating from Bengaluru, India (US region). Current risk assessment: LOW (Score: 25/100). The IP hosts standard web and SSH services with minimal threat indicators.
---
INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| **Organization** | DigitalOcean, LLC |
| **ASN** | 14061 |
| **BGP Prefix** | 168.144.80.0/20 |
| **Infrastructure Type** | Cloud Compute |
| **Geolocation** | Bengaluru, Karnataka, India |
| **Hosting** | Yes (Cloud Provider) |
---
NETWORK SERVICES
- HTTP (80/tcp): nginx/1.24.0 (Ubuntu) - Status 200, HTTP/1.1
- SSH (22/tcp): OpenSSH_9.6p1 Ubuntu-3ubuntu13.16
- TLS Certificate: None observed
- Email Authentication: SPF/DMARC not configured
---
THREAT ASSESSMENT
Overall Risk Score: 25 (LOW)
Threat Indicators:
- Blacklist Listings: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Abuse Confidence Score: Not applicable
Control Plane:
- DNSBL Listed: 1 of 8 total lists
- Operator Score: 0.1304 (Minimal)
- Route Stability: Unstable
---
NEIGHBORHOOD ANALYSIS (168.144.95.0/24)
Subnet Classification: Mostly Clean
| Metric | Value |
|---|---|
| **Abuse Density** | 1 |
| **Total Siblings** | 2 |
| **Active Siblings** | 2 |
| **Threat Siblings** | 2 |
| **Inherited Risk** | 5 |
Notable Neighbor:
- 168.144.95.137: Risk Score 65 (Medium Risk)
---
OBSERVATION HISTORY
Total Observations: 19 signals tracked
Key Historical Events:
- 2026-06-19: DNSBL listing detected (High Severity)
- 2026-06-19: Port scan activity recorded
- 2026-06-19: HTTP fingerprinting captured (nginx/1.24.0)
- 2026-06-28: Latest cloud infrastructure observation
Temporal Analysis:
- Ownership Changes: 0
- Threat Observation Count: 1
- Threat Persistence Days: 0
- Persistently Malicious: No
---
RELATIONSHIP GRAPH
Connected Entities: 25 relationships identified
Primary Relationship Type: Same Network (NET-168-144-0-0-1)
---
RECOMMENDED ACTIONS
Firewall/Blocking: No immediate blocking recommended. Risk score (25) falls below typical threshold for automated blocking.
Monitoring: Continue passive monitoring due to:
- Recent DNSBL listing activity
- Neighbor IP 168.144.95.137 showing elevated risk (65)
- Unstable BGP routing
Investigation Triggers:
- New threat indicators on any 168.144.95.x address
- Changes in service banners or TLS certificates
- Escalation in blacklist listings
---
ASSESSMENT
This IP represents standard cloud infrastructure with minimal threat posture. The single DNSBL listing and one medium-risk neighbor warrant awareness but do not justify immediate defensive action. SOC teams should maintain baseline monitoring while correlating any activity with the broader 168.144.95.0/24 subnet.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 25% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-14 01:08:49 UTC |
| Last Seen | 2026-06-28 00:04:27 UTC |
| Profile Built | 2026-06-28 18:09:25 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 22 |
Full dossier details are available via our API.