## IPDEBRIEF INTELLIGENCE BRIEFING
Subject: 67.205.179.252/32
Classification: Low Risk
Date: Current
EXECUTIVE SUMMARY
IP 67.205.179.252 is a low-risk cloud infrastructure endpoint hosted on DigitalOcean. The IP exhibits standard web server behavior with no active threat indicators. Current risk assessment indicates minimal operational concern.
OWNERSHIP & INFRASTRUCTURE
- Organization: DigitalOcean, LLC (ASN 14061)
- Network Role: CloudCompute / Web Server
- CIDR Block: 67.205.176.0/20
- Geolocation: North Bergen, NJ, US
- Infrastructure Type: Cloud-hosted (DigitalOcean)
NETWORK SERVICES
- Port 80/tcp: HTTP (nginx/1.24.0)
- Port 443/tcp: HTTPS (nginx/1.24.0)
- Port 22/tcp: SSH (OpenSSH_9.6p1 Ubuntu)
- Port 8080/tcp: HTTP-ALT
- TLS Certificate: Let's Encrypt (CN=api.dryveng.com)
THREAT ASSESSMENT
- Overall Risk Score: 30/100 (Low Risk)
- Abuse Confidence: Not elevated
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0
- Threat Feeds: None correlated
OBSERVATION HISTORY
Analysis of 23 historical observations reveals:
- Control Plane Signals: Minimal operator score (0.1304)
- Threat Persistence: Single threat observation recorded
- Ownership Stability: No ownership changes detected
- Recent Activity: DNSBL activity observed on June 18, 2026 (high severity listing)
- Current Status: Threat observation count: 1 (not persistently malicious)
NEIGHBORHOOD ANALYSIS
- Subnet: 67.205.179.0/24
- Abuse Density: 0 (clean)
- Threat Siblings: 1
- Classification: Mostly clean
- Inherited Risk: 2 (low)
NETWORK RELATIONSHIPS
- Total Relationships: 24
- Type: Same Network (DIGITALOCEAN-67-205-128-0)
- Pattern: Consistent DigitalOcean infrastructure footprint
RECOMMENDED ACTIONS
Based on current risk profile (score 30), no immediate blocking or mitigation actions are required. The IP represents standard cloud infrastructure with no active malicious indicators.
Recommended Security Posture:
- Allow standard inbound traffic (ports 80, 443)
- Monitor SSH traffic (port 22) for anomalous authentication
- No firewall rules required at this time
INTELLIGENCE NOTES
This IP operates within a legitimate DigitalOcean cloud environment. The presence of a Let's Encrypt certificate for api.dryveng.com indicates active service operation. Historical DNSBL activity warrants continued monitoring but does not indicate persistent malicious behavior. Continue standard threat monitoring protocols.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| 8080 | http-alt | tcp | β |
| Closed Ports | 25, 3389, 8443 (4 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | api.dryveng.com |
| Valid From | 2026-06-10T12:02:45+00:00 |
| Valid Until | 2026-09-08T12:02:44+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 0529065537C1B04BBDA1B8EC2441BFD4FC2D |
| Thumbprint | 93B73348C5F579AB29FCF017724AF288620099FB |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 43% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 27% | 10 | 18 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:33 UTC |
| Last Seen | 2026-06-27 09:10:57 UTC |
| Profile Built | 2026-06-28 03:16:09 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 28 |
Full dossier details are available via our API.