INTELLIGENCE BRIEFING: IP 164.92.189.151/32
Date: 2026-08-13
Classification: HIGH RISK
Assigned Analyst: SOC Intelligence Unit
---
**1. EXECUTIVE SUMMARY**
IP address 164.92.189.151 is classified as High Risk with an overall risk score of 80/100. The address is assigned to DigitalOcean, LLC (AS14061) and operates within the DO-13 network (164.92.64.0/18). While the immediate /24 subnet shows clean classification with zero abuse density, the IP has been flagged on four DNS blacklists and exhibits cloud hosting infrastructure patterns consistent with potential abuse vectors.
**2. OWNERSHIP AND INFRASTRUCTURE**
- Organization: DigitalOcean, LLC
- ASN: 14061
- Network Block: 164.92.64.0/18 (DO-13)
- Geolocation: Frankfurt am Main, Hesse, DE
- Infrastructure Type: Cloud Compute (isCloud: true, isHosting: true)
- Connection Type: Not detected (Firewalled / No Services)
The IP resolved to no open ports or active services during the latest scan, with no TLS certificates or HTTP banners observed. This suggests either a firewalled infrastructure or dormant state.
**3. THREAT INDICATORS**
- Risk Score: 80 (High Risk)
- DNSBL Listings: 4 out of 8 total blacklist entries
- Abuse Confidence: Listed on multiple threat feeds
- Campaign Correlation: No known campaign matches identified
- Threat Persistence: Not persistently malicious
The IP accumulated five threat pulses during the observation period, indicating active malicious behavior patterns.
**4. NETWORK NEIGHBORHOOD ANALYSIS**
The /24 subnet (164.92.189.0/24) containing this IP shows:
- Abuse Density: 0% (classified as "clean")
- Active Siblings: 0
- Threat Siblings: 0
- Total Neighbors: 0
This indicates the IP operates in isolation within its subnet, with no neighboring addresses flagged for abuse activity.
**5. OBSERVATION HISTORY**
Twelve signal observations were recorded. Key findings include:
- Recent observation (2026-08-13 15:10:43 UTC) flagged the IP with threat indicators and five associated pulse names
- One geolocation record placed the IP in US (latitude 37.751, longitude -97.822), contrasting with the primary DE location
- Operator score rated as "Minimal" (0.1304)
- No ownership changes detected over the observation period
**6. RELATIONSHIP MAPPING**
The relationship graph identifies two connections, both classified as "Same Network" pointing to the DO-13 network entity. No external relationships to hostnames, organizations, or certificates were discovered.
**7. RECOMMENDED ACTIONS**
Based on the threat profile, the following actions are recommended:
1. Block at perimeter firewall (iptables/nftables):
```
iptables -A INPUT -s 164.92.189.151/32 -j DROP
```
2. Apply to WAF rules (Cloudflare/AWS WAF):
```
block_ip 164.92.189.151
```
3. Monitor for lateral movement - Investigate if any outbound connections were initiated from this IP
4. Review DNSBL listings to determine specific blacklisting reasons and whether removal is warranted if the IP has been legitimately secured
---
END OF BRIEFING
*Report generated using IPDebrief intelligence platform data. All findings are based on observed signals and automated analysis.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DO-13 |
| CIDR Block | 164.92.64.0/18 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Caddy |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 32% | 2 | 3 |
| ownership | 30% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 26% | 10 | 17 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-11 05:40:43 UTC |
| Last Seen | 2026-08-30 15:42:21 UTC |
| Profile Built | 2026-08-30 15:45:37 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 25 |
Full dossier details are available via our API.