## IP Intelligence Briefing: 159.223.93.19
IP Address: 159.223.93.19/32
ASN: 14061 (DigitalOcean, LLC)
Network: DO-13 (159.223.0.0/16)
Geolocation: Singapore (SG)
Risk Classification: Moderate Risk (Score: 50)
---
Current Risk Profile
The IP address 159.223.93.19 is registered to DigitalOcean, LLC and operates within a cloud infrastructure environment. The current risk score of 50 reflects moderate risk with no known malicious indicators. The IP is classified as a cloud compute host with hosting capabilities enabled. No open ports were detected during service enumeration, and the IP does not serve as a proxy, Tor exit node, or VPN endpoint.
Network Context
The IP resides within the 159.223.93.0/24 subnet. Neighborhood analysis identified one sibling IP (159.223.93.39) with a matching risk score of 50. Subnet abuse density is zero. Both IPs maintain medium-risk classifications with no high-risk activity detected in the immediate neighborhood. The /16 block (159.223.0.0/16) is a DigitalOcean cloud infrastructure network.
Threat Indicators
No known threat indicators were associated with this IP. The address does not appear on any major threat feeds, is not listed as a known attacker, and is not identified as a spam source. Blacklist enumeration showed minimal presence with two DNSBL listings out of eight total lists checked.
Historical Observation
Fifteen signal observations were recorded. Geolocation data showed inconsistencies between Singapore (claimed) and United States (inferred from traceroute), indicating potential multi-tenant cloud routing or geographic spoofing. ICMP validation failed due to blocked probes. No persistent malicious behavior was observed, with threat observation count at zero. The IP has maintained consistent ownership without changes.
Related Entities
The IP shares its network block (DO-13) with three related network entities, all classified as same-network associations. No hostname, domain, or certificate relationships were identified.
---
Recommended Actions
Given the moderate risk classification and cloud hosting environment:
- Allow with monitoring: No immediate blocking recommended for legitimate cloud traffic
- Monitor for: Unusual outbound connections, data exfiltration attempts, or lateral movement
- Block if: Observed in malicious traffic patterns or associated with confirmed compromise events
- Note: The IP lacks active services and no open ports were detected, suggesting it may be dormant or misconfigured
---
Summary: This IP represents a standard DigitalOcean cloud infrastructure address with moderate risk classification. No active threat indicators were detected. The presence of sibling IPs at equal risk suggests this is part of a legitimate cloud tenant deployment. SOC analysts should treat this IP as low-priority unless associated with specific incident activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DO-13 |
| CIDR Block | 159.223.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-12 18:30:20 UTC |
| Last Seen | 2026-09-03 03:27:53 UTC |
| Profile Built | 2026-08-31 17:35:33 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.