# Intelligence Briefing: 165.22.189.163/32
## Executive Summary
IP address 165.22.189.163 is a DigitalOcean cloud infrastructure endpoint with low risk classification (risk score: 25/100). The asset operates as a hosting provider with SSH service exposure and minimal threat indicators. No immediate blocking is recommended, though geolocation validation anomalies warrant monitoring.
## Infrastructure Profile
- Organization: DigitalOcean, LLC (ASN: 14061)
- Geolocation: United States, North Bergen, NJ (geolocation confidence: low)
- Network Role: CloudCompute/Hosting infrastructure
- CIDR Block: 165.22.176.0/20
- BGP Prefix: 165.22.176.0/20
## Network Observations
- Open Services: Port 22/SSH (OpenSSH 8.9p1 Ubuntu-3ubuntu0.15)
- DNS Resolution: ptr hostname `prod-boron-nyc1-68.do.binaryedge.ninja`
- Associated Domain: binaryedge.ninja (binaryedge is a known threat intelligence platform)
- Blacklist Status: Not listed on major blacklists
- Reputation Sources: AlienVault OTX indicates threat association with 13 threat pulses
## Threat Intelligence Analysis
- Risk Classification: Low Risk (25/100)
- Known Malicious Activity: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Abuse Confidence Score: Not applicable
## Network Neighborhood Assessment
- Subnet: 165.22.189.0/24
- Abuse Density: 0% (clean)
- Threat Siblings: 1 detected
- Overall Classification: Mostly clean
## Historical Signal Analysis
Analysis of 21 observation records reveals:
- Consistent cloud infrastructure classification across all observations
- Geolocation validation failures detected (geoPlausible: false)
- RTT anomaly: 18ms measured vs 119.3ms minimum expected for 5,963km distance
- Threat observation count: 1
- No persistent malicious behavior detected
## Relationship Graph
- DNS Associations: Multiple hostnames mapping to binaryedge.ninja domain
- Network Affiliations: DIGITALOCEAN-165-22-0-0 network
- Total Relationships: 44 detected
## Recommended Actions
- Status: Monitor, no immediate blocking required
- Firewall Rules: None generated
- Risk Mitigation: Standard cloud security practices apply
- Observation: Track geolocation validation anomalies for potential routing issues
## Analyst Notes
The IP operates within DigitalOcean's cloud infrastructure with legitimate hosting purposes. While not flagged as malicious, the association with binaryedge.ninja (a threat intelligence platform) and geolocation validation inconsistencies suggest this endpoint may be used for reconnaissance or threat data collection activities. No blocking action recommended, but continued monitoring advised.
Classification: Low Priority | Last Updated: 2026-06-20
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | prod-boron-nyc1-68.do.binaryedge.ninja |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | prod-boron-nyc1-68.do.binaryedge.ninja |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 34% | 2 | 3 |
| Overall | 21% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-24 18:40:06 UTC |
| Last Seen | 2026-06-29 00:23:49 UTC |
| Profile Built | 2026-06-29 06:26:15 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.