# IP Intelligence Briefing: 157.245.229.117/32
## Executive Summary
This IP address represents a DigitalOcean cloud server in Santa Clara, California with a low-risk profile (score: 25). However, historical observations indicate intermittent proxy/compromised server behavior. The IP resolves to a domain associated with threat intelligence infrastructure (binaryedge.ninja) and has been listed on 1 of 8 DNS blacklists.
## Network Classification
- Owner: DigitalOcean, LLC (ASN 14061)
- Network: DIGITALOCEAN-157-245-0.0/16
- Infrastructure Type: Cloud compute (hosting infrastructure)
- Location: Santa Clara, California, United States
- Geolocation Consensus: Validated across multiple sources
## Threat Indicators
- Current Risk Score: 25 (Low Risk)
- DNSBL Status: Listed on 1 of 8 blacklists
- Known Campaigns: None detected
- Abuse Confidence Score: Not available
- Tor Exit Node: No
- Known Attacker: No
## Historical Analysis
Analysis of 23 observations reveals a change in threat profile:
- August 13, 2026: Flagged as "Compromised Server" proxy type by proxycheck-io with risk score of 66
- August 6, 2026: No malicious campaigns detected
- Threat Persistence: 0 days observed
- Operator Score: 0.2609 (labeled as "Basic")
## DNS Intelligence
- PTR Record: prod-krypton-sfo2-5.do.binaryedge.ninja
- Reverse DNS: Confirmed and forward-resolved to binaryedge.ninja
- Forward Hostnames: Single hostname association
- Email Authentication: SPF enabled, DMARC not configured
## Services
- Open Ports: TCP/22 (SSH)
- SSH Banner: OpenSSH_8.9p1 Ubuntu-3ubuntu0.16
- HTTP/TLS: No services detected
## Neighborhood Assessment
Subnet 157.245.229.0/24 shows:
- Abuse Density: 0
- Classification: Clean
- Active Siblings: 3 IPs (including subject)
- Threat Siblings: 0
Neighboring IPs:
- 157.245.229.210: Risk 25, Authority 60
- 157.245.229.234: Risk 0, Authority 50
## Recommended Actions
1. Monitor DNS Traffic: The hostname binaryedge.ninja is a known threat intelligence platform endpoint. Legitimate traffic to this domain is expected.
2. Review Proxy Associations: Historical data indicates the IP was recently flagged as a compromised proxy server. Correlate with current network traffic.
3. DNSBL Verification: Confirm the single DNSBL listing and evaluate impact on network reputation.
4. SSH Connection Logging: Monitor SSH port activity for unauthorized access attempts.
5. Blocklist Evaluation: If the DNSBL listing is for malicious activity, consider temporary blocking pending investigation.
## Conclusion
The IP 157.245.229.117 operates on DigitalOcean infrastructure and is currently classified as low risk. However, the historical proxy/compromised server designation and DNSBL listing warrant monitoring. The DNS association with binaryedge.ninja is consistent with threat intelligence operations and may represent legitimate defensive infrastructure. Continue monitoring for changes in risk profile or proxy behavior.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-157-245-0-0 |
| CIDR Block | 157.245.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | prod-krypton-sfo2-5.do.binaryedge.ninja |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | prod-krypton-sfo2-5.do.binaryedge.ninja |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-01 04:25:09 UTC |
| Last Seen | 2026-08-13 02:20:29 UTC |
| Profile Built | 2026-08-13 02:35:43 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.