# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 67.207.95.129/32
Classification: Moderate Risk | Date: 2026-08-06
---
## EXECUTIVE SUMMARY
IP address 67.207.95.129 presents a moderate risk profile (score: 50/100) with cloud-hosted infrastructure on DigitalOcean. The IP is currently classified as a clean endpoint with no active threat indicators, though it appears on 2 of 8 DNSBLs. No malicious campaigns or attacker signatures detected.
---
## INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| **Organization** | DigitalOcean, LLC |
| **ASN** | 14061 |
| **Network** | DIGITALOCEAN-67-207-64-0 |
| **CIDR Block** | 67.207.64.0/19 |
| **Geolocation** | US, New Jersey (North Bergen) |
| **Infrastructure Type** | CloudCompute |
| **Service Status** | Firewalled / No Services |
---
## THREAT INDICATORS
- Risk Score: 50 (Moderate)
- Blacklist Count: 0 active lists
- DNSBL Listed: 2/8 total lists
- Tor Exit Node: False
- Known Attacker: False
- Spam Source: False
- Threat Feeds: None detected
- Campaign Correlation: None
---
## NETWORK ENVIRONMENT
- Subnet: 67.207.95.129/24
- Abuse Density: 0.0 (Clean)
- Neighboring IPs: 0 discovered
- Classification: Clean
- Route Stability: False
- BGP Prefix: 67.207.80.0/20
- Transit Networks: Comcast, Cogent
---
## OBSERVATION HISTORY
Total Observations: 21 signals
Recent Activity:
- 2026-08-06 01:20: Certificate queries (0 certificates resolved)
- 2026-08-06 01:20: Operator score: Minimal (0.1304)
- 2026-07-31 05:25: Geolocation observed via Cogent transit at JFK, New York
Temporal Analysis:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Persistently Malicious: False
---
## RELATIONSHIP ANALYSIS
Connected Entities: 8 relationships identified
- All relationships map to same network (DIGITALOCEAN-67-207-64-0)
- No external hostname, organization, or certificate associations
- No correlated IPs detected
---
## RECOMMENDED SECURITY ACTIONS
Risk Score: 50 (Moderate) β Block recommended for defensive posture
| Platform | Rule/Action |
|---|---|
| **iptables** | `iptables -A INPUT -s 67.207.95.129 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 67.207.95.129 drop` |
| **nginx** | `deny 67.207.95.129;` |
| **pfSense** | `67.207.95.129/32` |
| **Cloudflare WAF** | Block 67.207.95.129 (IPDebrief risk score 50) |
| **AWS WAF** | Add 67.207.95.129/32 to IP set with description "IPDebrief risk 50" |
---
## ANALYST NOTES
1. Risk Context: Moderate risk score (50) primarily driven by DNSBL presence rather than active threat indicators.
2. Infrastructure: DigitalOcean cloud environment with no open services detected.
3. Neighborhood: Clean subnet with no abuse density or threat siblings.
4. Monitoring: Recommend continued monitoring for any changes in DNSBL status or emergence of threat indicators.
5. Action Threshold: Consider blocking based on organizational risk tolerance, as current indicators suggest opportunistic scanning rather than targeted attacks.
---
*Report generated by IPDebrief Intelligence Platform. Recommendations are probabilistic and should be validated against additional threat intelligence sources before implementation.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-67-207-64-0 |
| CIDR Block | 67.207.64.0/19 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 22% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-30 23:21:00 UTC |
| Last Seen | 2026-08-13 01:15:39 UTC |
| Profile Built | 2026-08-13 01:24:47 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.