# IP Intelligence Briefing: 165.22.225.218/32
Classification: HIGH RISK โ Cloud Infrastructure Node
Report Date: 2026-06-22
Analyst: IPDebrief Intelligence Team
---
## Executive Summary
IP 165.22.225.218 is classified as High Risk (Score: 80/100) and hosted on DigitalOcean cloud infrastructure. The IP is listed on 4 of 8 DNSBLs with high-severity ratings. While no direct threat indicators or known campaigns were identified, the blacklist presence warrants defensive monitoring. No active services or open ports were detected; the host appears to be firewalled or dormant.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **IP Address** | 165.22.225.218/32 |
| **Risk Score** | 80 (High) |
| **Infrastructure Type** | CloudCompute (DigitalOcean) |
| **ASN** | 14061 |
| **BGP Prefix** | 165.22.224.0/20 |
| **Geolocation** | Toronto, ON, CA |
| **Country** | Canada (CA) |
| **Ownership** | DigitalOcean, LLC (US RIR) |
| **Open Ports** | None detected |
| **DNSBL Listings** | 4 of 8 total lists |
---
## Threat Indicators
- Reputation: High Risk
- Blacklist Presence: Listed on multiple threat feeds (severity: high)
- Campaign Affiliation: None identified
- Known Attacker Status: Not confirmed
- Tor Exit Node: No
- Spam Source: No
- Tor Network: No
Notable: No active threat indicators or known malicious campaigns were observed. The IP appears to be a dormant or non-responsive cloud endpoint with firewall protection.
---
## Observation History
Total Observations: 11 signals recorded
Recent Activity (2026-06-22):
- DNSSEC validation: Valid on reverse DNS zone (218.225.22.165.in-addr.arpa)
- ASN confirmation: 14061 (DigitalOcean)
- Listing activity: 8 total blacklist listings, 4 active at time of observation
Temporal Analysis: No persistent malicious behavior detected. Average ownership days: N/A. Threat observation count: 1.
---
## Network Relationships
- Related Entities: None identified
- Subnet Analysis: 165.22.225.0/24 โ No sibling IPs detected
- Neighborhood Risk: Abuse density: 0; No high-risk neighbors identified
---
## Recommended Actions
Immediate:
- Monitor for connection attempts from this IP. If inbound traffic is observed, consider blocking at perimeter firewall.
- Verify if this IP corresponds to any internal assets or allowed services.
Defensive Configuration:
- Add to blocklist if no legitimate business need exists.
- Review firewall rules for DigitalOcean-originated traffic in the 165.22.224.0/20 range.
Monitoring:
- Track future blacklist additions/changes via automated reputation monitoring.
- Investigate if this IP appears in threat intelligence feeds relevant to your threat landscape.
---
Summary Assessment: This IP represents a moderate-to-high risk cloud infrastructure node with confirmed blacklist presence but no active malicious behavior observed. While the risk score is elevated (80), the lack of open services and known campaigns suggests it may be a dormant or repurposed host. Continue monitoring for behavioral changes.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-165-22-0-0 |
| CIDR Block | 165.22.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 8% | 2 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-21 00:08:18 UTC |
| Last Seen | 2026-06-26 18:10:44 UTC |
| Profile Built | 2026-06-22 04:24:31 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.