# IP Intelligence Briefing: 157.245.170.187/32
Classification: Low Risk with Notable Anomalies
Date: 2026-08-13
Assigned Risk Score: 25/100
## Executive Summary
IP address 157.245.170.187 is a DigitalOcean cloud compute instance registered in Santa Clara, CA. While current risk profile shows low risk, historical observations indicate the IP was previously identified as a compromised server operating as a proxy. The DNS configuration points to the binaryedge.ninja infrastructure, which warrants monitoring.
## Ownership & Infrastructure
| Attribute | Value |
|---|---|
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network | DIGITALOCEAN-157-245-0.0/16 |
| Infrastructure Type | Cloud Compute |
| Classification | Cloud-hosted service |
## Technical Profile
- DNS Resolution: prod-neon-sfo2-21.do.binaryedge.ninja (binaryedge.ninja)
- Open Services: SSH (TCP/22) - OpenSSH 8.9p1 Ubuntu-3ubuntu0.16
- Email Authentication: SPF enabled, DMARC not configured
- Geolocation: Santa Clara, CA, US (geolocation consensus: true, but RTT validation shows 8862.5km with 85ms RTTβphysically implausible)
## Threat Indicators
- Current Blacklist Status: Not listed on major DNSBLs (0 hits)
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Campaign Correlation: None detected
## Historical Analysis
22 total observations recorded. Notable finding:
2026-08-13 02:22:04 UTC
- Flagged as Compromised Server (proxy type)
- Risk Score: 66
- Source: proxycheck-io
- ISP: DigitalOcean, LLC
This indicates the IP may have been temporarily misconfigured or compromised for proxying activities. The same observation date shows additional operator scoring (0.2609) and DNSSEC validation.
## Network Neighborhood
- Subnet: 157.245.170.0/24
- Abuse Density: 0 (clean)
- Threat Siblings: 0
- No neighboring IPs with elevated risk identified
## Recommended Actions
1. Monitor DNS Activity: The IP resolves to binaryedge.ninja, a threat intelligence platform. Verify if this is intended infrastructure or unauthorized usage.
2. SSH Exposure: Port 22 is open. Assess if this SSH instance is legitimate or could be exploited for lateral movement.
3. Historical Proxy Flag: Investigate why the IP was flagged as a compromised proxy on 2026-08-13. This may indicate prior abuse or misconfiguration.
4. Geolocation Anomaly: The RTT distance violation (8862km with 85ms RTT) suggests geolocation data may be spoofed or inaccurate.
5. DMARC Configuration: Recommend enabling DMARC records if email services are hosted on this infrastructure.
## Conclusion
The IP presents a low current risk profile but requires attention due to historical proxy detection and implausible geolocation data. Recommend continued monitoring of DNS activity and SSH access patterns. No immediate blocking advised, but maintain awareness of the binaryedge.ninja DNS association and prior compromise indicators.
---
*Intelligence generated from IPDebrief platform data. All information sourced from automated observations.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-157-245-0-0 |
| CIDR Block | 157.245.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | prod-neon-sfo2-21.do.binaryedge.ninja |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | prod-neon-sfo2-21.do.binaryedge.ninja |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-01 04:25:09 UTC |
| Last Seen | 2026-08-13 02:20:19 UTC |
| Profile Built | 2026-08-13 02:35:44 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.