# INTELLIGENCE BRIEFING: IP 165.22.22.31/32
## Executive Summary
IP address 165.22.22.31/32 is classified as LOW RISK with a risk score of 0. The address belongs to DigitalOcean, LLC (ASN 14061) and is hosted in Frankfurt am Main, Germany. No malicious indicators, campaign associations, or threat feed listings were observed. The IP operates standard cloud infrastructure with HTTP and SSH services enabled.
---
## Profile Overview
Ownership & Registration:
- Organization: DigitalOcean, LLC
- Network Name: DIGITALOCEAN-165-22-0-0
- ASN: 14061
- CIDR Block: 165.22.0.0/16
- RIR: ARIN
- Abuse Contact: Available via RDAP
Geolocation:
- Country: Germany (DE)
- Region: Hesse
- City: Frankfurt am Main
- Coordinates: Latitude/longitude not provided
- Timezone: Europe/Berlin
Infrastructure Classification:
- Infrastructure Type: CloudCompute
- Connection Type: Cloud hosting
- Is Cloud Provider: Yes
- Is Hosting: Yes
- Is CDN/VPN/Proxy/Tor: No
---
## Network Services & Fingerprinting
Open Ports:
| Port | Protocol | Service | Status |
|---|---|---|---|
| 80 | TCP | HTTP | Open |
| 22 | TCP | SSH | Open |
Server Banner: nginx/1.24.0 (Ubuntu)
Server Type: nginx 1.24.0
HTTP Version: 1.1
Response Time: 602ms
Status Code: 200
DNS Analysis:
- PTR Hostnames: None detected
- Forward Resolution: Not confirmed
- Hosted Domains: 0
- Email Authentication: No SPF/DMARC records detected
---
## Threat Intelligence Assessment
Threat Indicators:
- Reputation Sources: None
- Abuse Confidence Score: Not applicable (low risk)
- Is Tor Exit: No
- Is Known Attacker: No
- Is Spam Source: No
- Blacklist Count: 0
- Known Campaigns: None
Threat Feeds: Empty
Control Plane Analysis:
- Origin ASN: 14061
- BGP Prefix: 165.22.16.0/20
- Route Stability: Not stable
- DNSSEC Valid: Yes
- DNSBL Listings: 0 (total lists: 8)
- Operator Score: 0.1304 (Minimal)
---
## Neighborhood Analysis
Subnet: 165.22.22.31/24
- Abuse Density: 0 (clean)
- Classification: Clean
- Inherited Risk: 0
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 0
Risk Distribution (Subnet):
- High Risk: 0
- Medium Risk: 0
- Low Risk: 0
---
## Historical Observations
Observation Count: 15 signals tracked
Recent Signals (2026-07-30):
1. Server Fingerprint: nginx/1.24.0 (HTTP/1.1) - Confidence: 80%
- Status: 200, TTFB: 602ms
- No HSTS, CSP, or referrer policy headers
2. Port Scan: Ports 80 and 22 detected - Confidence: 90%
- SSH version: OpenSSH_9.6p1 Ubuntu-3ubuntu13.18
3. Infrastructure Classification: Cloud hosting (DigitalOcean) - Confidence: 90%
- Not residential, VPN, proxy, or Tor
4. Ownership History: No changes detected - Confidence: 85%
- Persistently malicious: No
Temporal Analysis:
- Ownership changes: 0
- Threat observation count: 0
- Threat persistence days: 0
- Persistently malicious: False
---
## Relationship Graph
Detected Relationships: 4
- Same Network: DIGITALOCEAN-165-22-0-0 (repeated associations)
---
## Recommended Actions
Security Recommendations: None
- Risk score: 0
- No firewall rules generated
- No immediate mitigation required
Assessment: The IP address presents no actionable threat indicators. Standard monitoring practices are sufficient. No blocking or rate-limiting measures are recommended at this time.
---
Classification: LOW RISK
Last Updated: 2026-07-30
Intel Source: IPDebrief
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-165-22-0-0 |
| CIDR Block | 165.22.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 35% | 2 | 4 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 27% | 2 | 2 |
| Overall | 25% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-28 10:06:17 UTC |
| Last Seen | 2026-08-12 22:23:51 UTC |
| Profile Built | 2026-08-12 22:28:13 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 21 |
Full dossier details are available via our API.