IPDebrief

159.89.51.105

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 159.89.51.105/32

Classification: Low Risk / Cloud Infrastructure

Analysis Date: 2026-06-19

Prepared For: SOC Operations Team

---

## Executive Summary

IP address 159.89.51.105 is a DigitalOcean cloud compute endpoint located in North Bergen, New Jersey, USA. The IP presents a low-risk profile with a risk score of 25/100. No active malicious indicators were observed, and the IP operates as a standard cloud infrastructure asset without open services.

---

## Ownership & Infrastructure

AttributeValue
**Organization**DigitalOcean, LLC
**ASN**14061
**BGP Prefix**159.89.48.0/21
**Infrastructure Type**CloudCompute
**Location**US, NJ, North Bergen
**Geolocation Confidence**65%
**DNSSEC Valid**Yes

The IP is part of DigitalOcean's cloud infrastructure with route stability marked as false. The control plane shows an operator score of 0.1304 (Minimal) and the subnet is classified as "mostly_clean" with a 0.5 abuse density rating.

---

## Threat Assessment

Current Risk Score: 25/100 (Low Risk)

IndicatorStatus
Tor Exit NodeNo
Known AttackerNo
Spam SourceNo
Blacklist Count0
DNSBL Listed1 of 8
Known CampaignsNone

No threat indicators were detected. The IP is not associated with any known threat campaigns or malicious activity feeds.

---

## Network Services & DNS

Service Status: Firewalled / No Services Detected

CheckResult
Open PortsNone
TLS CertificateNo
HTTP TitleNo
Server BannerNo
Hosted Domains0
PTR HostnamesNone
Forward ResolutionNot Confirmed

Email authentication records (SPF/DMARC) are absent. The IP shows no active service exposure, indicating it is either a backend service or properly hardened cloud instance.

---

## Neighborhood Analysis (159.89.51.0/24)

MetricValue
Total Siblings2
Active Siblings2
Threat Siblings1
Abuse Density0.5
Inherited Risk2

The /24 subnet contains minimal activity with one threat-adjacent sibling IP (159.89.51.248, Risk Score: 25). The subnet overall remains classified as "mostly_clean."

---

## Historical Observations

Analysis of 20 historical signals (2026-06-14 to 2026-06-19) reveals:

The IP has maintained consistent cloud infrastructure classification throughout the observation period with no escalation in threat posture.

---

## Relationship Graph

21 relationship entries identified, all mapping to "Same Network" targets under the DIGITALOCEAN-159-89-0-0 network block. No external hostname, organization, or certificate relationships were detected beyond the provider network.

---

## Recommended Actions

1. Allow with Monitoring: The IP presents a low-risk profile typical of cloud infrastructure. Standard allow policies are appropriate.

2. Monitor Subnet: One threat-adjacent sibling IP exists in the /24. Monitor for coordinated activity.

3. No Blocking Required: No actionable threat indicators warrant blocking or rate-limiting at this time.

---

Intelligence Confidence: High

Data Sources: IPDebrief Profile, History, Relationships, Neighborhood Analysis

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionNJ
CityNorth Bergen
Timezoneβ€”
Latitude40.80
Longitude-74.02

🏒 Ownership & Registration

OrganizationDigitalOcean, LLC
ASNAS14061
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
22%
24
routing
8%
11
services
15%
22
ownership
17%
23
reputation
24%
13
geolocation
33%
23
Overall20%1016
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-12 21:54:06 UTC
Last Seen2026-06-27 22:00:37 UTC
Profile Built2026-06-28 16:05:11 UTC
Data FreshnessLive
Signal Types19
Total Observations23
πŸ” 19 signal types Β· 23 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.