# IP Intelligence Briefing: 159.65.1.75/32
## Executive Summary
IP address 159.65.1.75 operates within a DigitalOcean cloud infrastructure environment in Singapore. The IP carries a moderate risk score of 50 with no direct threat indicators, but exhibits behavioral patterns consistent with cloud hosting environments. Recommended defensive posture is monitoring rather than blocking.
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **IP Address** | 159.65.1.75/32 |
| **Risk Score** | 50 (Moderate Risk) |
| **Provider** | DigitalOcean, LLC (ASN 14061) |
| **Network** | DIGITALOCEAN-159-65-0-0 /16 |
| **Location** | Singapore (SG) |
| **Infrastructure Type** | CloudCompute |
| **Classification** | Cloud Hosting |
## Threat Indicators
- Blacklist Status: Not blacklisted (0 entries)
- DNSBL Presence: Listed on 2 of 8 threat feeds
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Active Threats: None detected
- Campaign Associations: None identified
## Network Behavior
- Open Ports: None detected (service shows as "Firewalled / No Services")
- SSH Banner: SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18
- TLS Services: None observed
- HTTP Services: None observed
- DNS Records: No PTR records or forward resolution
## Observation History
Fourteen observations recorded between 2026-07-31. Key findings:
- Multiple port scan activities detected
- SSH service enumeration observed
- Operator classification: "Minimal" (score: 0.1304)
- Geolocation consensus: Singapore (90% confidence)
- One lower-confidence US geolocation signal (35% confidence)
- No persistent malicious behavior observed
## Subnet Analysis
159.65.1.75/24 Neighborhood:
- Abuse Density: 0% (low)
- Neighbor Count: 1 active sibling (159.65.1.200)
- Subnet Risk Distribution: 1 low risk, 0 medium, 0 high
- Inherited Risk: Minimal
## Related Entities
Three relationship entries identified, all pointing to the parent network DIGITALOCEAN-159-65-0-0. No certificate associations, hostname links, or organization-level connections beyond the network boundary.
## Defensive Recommendations
The IP presents a moderate risk profile typical of legitimate cloud hosting infrastructure. However, the following firewall rules are recommended for defensive hardening:
Immediate Actions:
- iptables: `iptables -A INPUT -s 159.65.1.75 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 159.65.1.75 drop`
- Cloudflare WAF: Block IP with risk score 50
- AWS WAF: Add 159.65.1.75/32 to blocked addresses
Contextual Considerations:
- Block only if traffic patterns indicate malicious intent
- Cloud hosting environment may be legitimate business infrastructure
- Monitor for behavioral changes over time
- Consider geolocation-based filtering if Singapore traffic is not expected
## Conclusion
This IP address represents cloud infrastructure with no current malicious indicators. The moderate risk score reflects the cloud hosting classification and minor DNSBL presence rather than active threats. Maintain monitoring posture and evaluate blocking decisions based on observed traffic patterns rather than IP reputation alone.
---
*Intelligence generated by IPDebrief. Data timestamp: 2026-07-31.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-159-65-0-0 |
| CIDR Block | 159.65.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 22 | ssh | tcp | |
| 3389 | rdp | tcp | β |
| Closed Ports | 25, 443, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 37% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 26% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-30 04:58:31 UTC |
| Last Seen | 2026-08-13 00:23:43 UTC |
| Profile Built | 2026-08-13 00:32:46 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.