# IP Intelligence Briefing: 198.199.70.112
Classification: Low Risk | Status: Active | Date Generated: 2026-06-21
---
## Executive Summary
IP address 198.199.70.112 is a DigitalOcean cloud compute endpoint with minimal threat indicators. The address maintains a risk score of 25 (Low Risk) and demonstrates stable operational characteristics typical of legitimate cloud infrastructure. No active threat campaigns or persistent malicious behavior detected.
---
## Asset Profile
Ownership & Network:
- Organization: DigitalOcean, LLC (ASN: 14061)
- Network: DIGITALOCEAN-198-199-64-0 (198.199.64.0/18)
- Infrastructure Type: CloudCompute (Cloud Hosting)
- Geolocation: United States (North Bergen, NJ)
Risk Assessment:
- Overall Risk Score: 25/100 (Low Risk)
- Abuse Confidence: Not applicable
- Blacklist Status: 0 blacklists
- DNSBL Status: 1 listing out of 8 queried (minimal impact)
- Threat Persistence: None detected
---
## Threat Indicators
Active Signals:
- No open ports detected
- No known attacker associations
- No Tor exit node activity
- No proxy or CDN functionality
- No known spam source activity
- No threat feed matches
Control Plane Analysis:
- Route stability: Unstable (route changes detected)
- Operator Score: 0.1304 (Minimal)
- DNSSEC: Valid
- IRR Consistency: Not verified
---
## Neighborhood Analysis
Subnet Context (198.199.70.0/24):
- Abuse Density: 1 (Low)
- Classification: Mostly Clean
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
The IP shares a subnet with minimal malicious activity. No significant correlation with neighboring threat actors observed.
---
## Observation History
Temporal Analysis (19 Total Observations):
- Observation Period: Recent monitoring window
- Ownership Changes: 0 (stable ownership)
- Threat Observation Count: 1
- Persistence Status: Not persistently malicious
Historical Signals Include:
- Subnet classification (mostly_clean)
- Inherited risk assessment (2/100)
- Cloud infrastructure confirmation
- Geographic consistency validation
---
## Relationship Network
Connected Entities:
- All relationships map to DIGITALOCEAN-198-199-64-0 network
- No external organizational or certificate associations
- No hostname or domain relationships detected
---
## Security Actions
Recommendation Status: No automated actions required
Firewall Configuration:
- No blocking or rate-limiting rules recommended
- Standard allow policies applicable
Monitoring Guidance:
- Continue routine monitoring
- No immediate escalation required
- Consider context-aware correlation with other DigitalOcean infrastructure
---
## Intelligence Assessment
The IP 198.199.70.112 represents legitimate cloud infrastructure with low-risk characteristics. The DigitalOcean hosting environment shows standard operational patterns. While the control plane indicates some route instability, this is consistent with dynamic cloud environments rather than malicious activity. No actionable threat indicators warrant immediate defensive measures.
Recommendation: Monitor as part of routine cloud infrastructure baseline. No immediate security actions required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-198-199-64-0 |
| CIDR Block | 198.199.64.0/18 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 24% | 2 | 3 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-30 00:19:55 UTC |
| Last Seen | 2026-06-29 06:59:22 UTC |
| Profile Built | 2026-06-29 07:07:49 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 21 |
Full dossier details are available via our API.