IP INTELLIGENCE BRIEFING: 159.89.173.223/32
Classification: LOW RISK | Risk Score: 25 | Last Updated: 2026-08-06
---
OWNERSHIP & INFRASTRUCTURE
The IP address 159.89.173.223 is assigned to DigitalOcean, LLC (ASN 14061) within the DIGITALOCEAN-159-89-0-0 network block. Infrastructure classification identifies this as a cloud compute host with hosted domain capabilities, operating in the Bengaluru, Karnataka region of India. The IP is not flagged as CDN, VPN, proxy, Tor, mobile, or residential infrastructure.
THREAT INDICATORS
Current threat assessment shows no active indicators. The IP is not listed as a Tor exit node, known attacker, or spam source. Blacklist enumeration returned zero matches. No known threat campaigns have been correlated with this address. Abuse confidence scoring remains uncalculated.
NETWORK SERVICES & ENDPOINTS
Active service enumeration reveals ports 80 (HTTP), 443 (HTTPS), and 22 (SSH) in operation. HTTP probing returns status code 503 (Service Unavailable). HTTP/2 protocol is enabled. TLS certificate analysis identifies a Traefik default certificate (TRAEFIK DEFAULT CERT) with self-signed characteristics. SSH banner indicates OpenSSH version 9.6p1 Ubuntu-3ubuntu13.18.
DNS & EMAIL AUTHENTICATION
No PTR record resolution available. Forward DNS resolution is not confirmed. No hosted domains are associated with this IP. Email authentication records (SPF, DMARC) are absent. DNSSEC validation is confirmed.
CONTROL PLANE & ROUTING
BGP origin ASN 14061 announces prefix 159.89.160.0/20. No route changes detected in the past 30 days. The IP is listed on one of eight queried DNS blacklists. Operator scoring remains neutral. Route stability is not currently confirmed.
GEOLOCATION VALIDATION
Geolocation consensus places the IP in India (IN), Karnataka region, Bengaluru city. Distance measurement from probe location is 7,581.6 km. ICMP validation is blocked, resulting in unverified latency data. Minimum possible RTT estimated at 151.6 ms.
OBSERVATION HISTORY (16 RECORDS)
Historical signal analysis shows consistent low-risk behavior over the observation period. Subnet classification remains "clean" with zero threat siblings. Inherited risk scores show no elevation. Geo validation attempts continue to encounter ICMP blocking. HTTP status codes persist at 503 across observations. TLS scanning confirms service availability on expected ports.
NETWORK RELATIONSHIPS
Relationship graph shows four connections to the DigitalOcean network (DIGITALOCEAN-159-89-0-0). No cross-organizational or cross-network relationships detected.
NEIGHBORHOOD ANALYSIS
The /24 subnet (159.89.173.0/24) contains one sibling IP: 159.89.173.248. Subnet abuse density is zero. Risk distribution indicates low-risk classification for both the subject IP and its neighbor. No threat siblings observed in the immediate subnet.
---
INTELLIGENCE SUMMARY
This IP address operates as a DigitalOcean cloud hosting resource in India with standard web server configuration. Current threat intelligence indicates low-risk operation with no active malicious indicators. The 503 service status suggests either maintenance, load balancing, or backend service issues rather than malicious behavior. Subnet neighborhood analysis confirms benign operation across the /24 block. No immediate blocking or mitigation actions are recommended based on current threat profile.
RECOMMENDED ACTIONS
- Monitor for changes in HTTP status codes (currently 503)
- Maintain awareness of subnet abuse density (currently zero)
- No firewall rules or blocking recommended at this time
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-159-89-0-0 |
| CIDR Block | 159.89.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
๐ TLS Certificate
| SANs | 42164780dad0d1d82f0b7c4716c4519f.a875d0d3d5caab9d4539d154adc67c0e.traefik.default |
| Valid From | 2026-08-02T11:55:28+00:00 |
| Valid Until | 2027-08-02T11:55:28+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 365 days |
| Serial Number | 00B2810021DBE5A6EE69C2D518BD3AF76E |
| Thumbprint | B06CA6835F7CDDB826D8AEC919A1D40D9D1F0DB2 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 35% | 2 | 3 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 30% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-02 23:10:00 UTC |
| Last Seen | 2026-08-13 04:12:16 UTC |
| Profile Built | 2026-08-13 04:26:38 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.