IPDebrief

80.240.128.52

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 80.240.128.52/32

Date: 2026-06-26

IP Address: 80.240.128.52

Overall Risk Assessment: Moderate Risk (Score: 40/100)

## Executive Summary

IP 80.240.128.52 operates as a web server within DigitalOcean's Amsterdam infrastructure. The address demonstrates moderate risk characteristics with minimal threat indicators currently observed. The IP resolves to a DigitalOcean cloud instance with standard web services (HTTP/HTTPS) and SSH access. No active malicious campaigns or known attacker associations were identified.

## Technical Profile

Ownership & Network Infrastructure

Services & Network Signatures

Control Plane Data

## Threat Indicators

Current Threat Profile

Temporal Analysis

Signal History

Recent observations indicate consistent geolocation inference pointing to Netherlands with RTT measurements averaging 109ms (minimum plausible 2.3ms). HTTP fingerprinting confirmed Apache/2 server with status code 200 responses. No significant signal degradation or escalation patterns observed within the observation window.

## Neighborhood Analysis

Subnet Context (80.240.128.0/24)

Relationship Graph

## Security Recommendations

Immediate Actions

1. Monitoring: Continue monitoring for SSH (port 22) brute force attempts typical of cloud hosting environments

2. DNSBL Review: Investigate the 2 DNSBL listings to determine listing reasons and potential remediation

3. TLS Validation: Verify self-signed certificate legitimacy if this IP is in your trust chain

Firewall Rules (iptables)

```bash

# Block DNSBL-listed connections (adjust based on specific lists)

iptables -A INPUT -s <dnsbl-ip-range> -j DROP

# Allow standard web traffic from known ranges

iptables -A INPUT -p tcp --dport 80 -j ACCEPT

iptables -A INPUT -p tcp --dport 443 -j ACCEPT

# Log SSH attempts for analysis

iptables -A INPUT -p tcp --dport 22 -j LOG

```

Additional Considerations

## Conclusion

IP 80.240.128.52 represents a standard DigitalOcean cloud web server with moderate baseline risk. The presence of 2 DNSBL listings warrants investigation, but no active malicious behavior was observed. The subnet shows minimal abuse density with only 1 threat sibling. Recommended approach is continued monitoring rather than immediate blocking, with specific attention to DNSBL resolution and SSH access patterns.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands
RegionNH
CityAmsterdam
TimezoneEurope/Amsterdam
Latitude52.13
Longitude5.29

๐Ÿข Ownership & Registration

Organizationdigitalocean
ASNAS14061
Network Nameโ€”
CIDR Blockโ€”
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRcm15.bitchanger.org
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamescm15.bitchanger.org

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
ServerApache/2
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_7.4

๐Ÿ” TLS Certificate

A self-signed certificate was detected. This is common for development servers, internal services, or IoT devices.
โš ๏ธ
E=webmaster@localhost, CN=localhost, OU=none, O=none, L=Sometown, S=Someprovince, C=US
Issued by E=webmaster@localhost, CN=localhost, OU=none, O=none, L=Sometown, S=Someprovince, C=US
Self-signed: Yes
SANsNone
Valid From2021-09-24T09:39:42+00:00
Valid Until2049-02-08T09:39:42+00:00
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
Signature Algorithmsha256RSA
Validity Period9999 days
Serial Number00E901178B3E17BB5F
Thumbprint1CFCE17D0E70029FDB4C458706AFCF6C365AC224

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
36%
26
routing
8%
11
services
25%
23
ownership
24%
23
reputation
26%
13
geolocation
35%
23
Overall26%1019
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMixed Signals (68%) โ€” 2 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Geo sources disagree on country: US, NL
โš  TLS certificate claims US but primary geo says NL

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-11 21:11:33 UTC
Last Seen2026-06-27 20:16:44 UTC
Profile Built2026-06-28 14:21:16 UTC
Data FreshnessLive
Signal Types24
Total Observations31
๐Ÿ” 24 signal types ยท 31 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.