# IP Intelligence Briefing: 159.89.30.252/32
Classification: Moderate Risk Cloud Infrastructure
Date: 2026-06-21
Analyst: Automated Intelligence System
---
## Executive Summary
IP address 159.89.30.252 is a DigitalOcean cloud-hosted system located in Frankfurt am Main, Germany (AS14061). Risk assessment returns moderate (score: 40/100) with no known active threat indicators, though the IP appears on 2 of 8 DNSBLs and one threat sibling exists within the /24 subnet.
---
## Network & Ownership Profile
| Attribute | Value |
|---|---|
| **Organization** | DigitalOcean, LLC |
| **ASN** | 14061 (DIGITALOCEAN-159-89-0-0) |
| **Network Block** | 159.89.0.0/16 |
| **Geolocation** | Frankfurt am Main, Germany (DE) |
| **Infrastructure Type** | CloudCompute |
| **Route Stability** | Stable (no changes in 30 days) |
| **Delegation Age** | 5,007 days |
---
## Observed Services & Signatures
- Open Ports: TCP/22 (SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16)
- TLS Certificate: None detected
- HTTP Services: None detected
- DNS Records: No PTR records; no reverse resolution
- Email Reputation: No SPF/DMARC configuration
---
## Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Active Threat Feeds: None
- Campaign Associations: None
- Blacklist Status: Listed on 2 of 8 DNSBLs
---
## Neighborhood Analysis (159.89.30.0/24)
- Abuse Density: 1 (low)
- Classification: Mostly clean
- Total Siblings: 1 active
- Threat Siblings: 1 identified within subnet
---
## Temporal Analysis
- Threat Persistence: 0 days
- Ownership Changes: 0
- Recent Observations: 20 signals over 24-hour period
- Risk Trend: Stable (no significant escalation)
---
## Recommended Actions
Immediate: No active threat indicators detected. Monitoring recommended.
Firewall Rules:
- `iptables`: `iptables -A INPUT -s 159.89.30.252 -j DROP`
- `nftables`: `nft add rule inet filter input ip saddr 159.89.30.252 drop`
- `nginx`: `deny 159.89.30.252;`
- `Cloudflare WAF`: Block IP with expression `ip.src eq 159.89.30.252`
- `AWS WAF`: Add to allowed/blocked list as `159.89.30.252/32`
---
## Intelligence Assessment
This IP represents a standard cloud-hosted endpoint with minimal threat indicators. The moderate risk score (40) likely reflects general cloud infrastructure risk rather than malicious activity. The presence on DNSBLs may indicate previous reputation issues or false positives. SOC teams should monitor for any changes in scanning behavior or service offerings, particularly given the single SSH port exposure common in cloud environments.
Threat Level: LOW-MEDIUM
Recommended Action: Monitor; no immediate block required without additional context.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-159-89-0-0 |
| CIDR Block | 159.89.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 24% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 30% | 3 | 4 |
| reputation | 22% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 24% | 12 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-27 13:16:50 UTC |
| Last Seen | 2026-06-29 04:14:30 UTC |
| Profile Built | 2026-06-29 04:18:03 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.