# IP Intelligence Briefing: 165.22.248.68
Classification: Cloud Infrastructure Address (DigitalOcean)
Risk Level: Moderate (Score: 50/100)
Date: 2026-08-13
---
## Summary
The target IP 165.22.248.68 is a cloud compute instance hosted by DigitalOcean, LLC within the 165.22.0.0/16 CIDR block. The address shows moderate risk characteristics but no active threat indicators. The subnet environment maintains a clean classification with zero abuse density.
## Ownership and Infrastructure
- Organization: DigitalOcean, LLC (ASN 14061)
- Network: DIGITALOCEAN-165-22-0-0 / 165.22.0.0/16
- Infrastructure Type: CloudCompute
- Registration: ARIN registry
## Network Characteristics
- Classification: Cloud hosting environment with firewall configuration
- Service Status: No open services detected
- DNS Resolution: No PTR records, no forward resolution confirmed
- Hosting Profile: Non-residential cloud infrastructure
## Geolocation Data
Multiple geolocation sources report conflicting data:
- Primary consensus: Singapore (SG)
- Secondary reports: United States (CO)
This discrepancy warrants awareness but does not indicate malicious activity.
## Threat Assessment
- Abuse Confidence: Not scored
- Blacklist Presence: Listed on 2 of 8 DNSBLs
- Threat Indicators: None detected
- Known Campaigns: None associated
- Tor Exit: No
- Known Attacker: No
- Spam Source: No
## Neighborhood Analysis
Subnet 165.22.248.0/24 maintains clean status with the following characteristics:
- Total Siblings: 3
- Active Siblings: 2
- Threat Siblings: 0
- Abuse Density: 0 (Clean)
Neighbor IP Risk Profile:
| IP Address | Risk Score | Authority Score | Classification |
|---|---|---|---|
| 165.22.248.57 | 25 | 50 | Low |
| 165.22.248.213 | 50 | 50 | Medium |
## Historical Observations
13 signal observations recorded with the following trends:
- Ownership signals stable with zero changes
- No persistent malicious activity detected
- Subnet classification remains "clean" throughout observation period
- No significant geolocation drift beyond initial conflicts
## Relationship Graph
Three relationships identified, all linking to the parent network DIGITALOCEAN-165-22-0-0. No hostname, certificate, or external organization relationships detected beyond network boundaries.
## Recommendations for SOC Analysts
1. Monitor: Track the 2 DNSBL listings to determine source and relevance
2. Context: The moderate risk score (50) is typical for cloud infrastructure with no active services
3. Correlation: Review neighboring IPs 165.22.248.57 and 165.22.248.213 for potential related activity
4. Geolocation: Investigate the Singapore/US discrepancy if location accuracy is mission-critical
5. No Immediate Action Required: No active threat indicators or malicious patterns observed
---
*Intelligence generated from IPDebrief platform data. Analysis reflects current observational state.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-165-22-0-0 |
| CIDR Block | 165.22.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | nginx/1.24.0 |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 05E91285A45DF023B037DDEE78675A858402 |
| Thumbprint | 219F6CBB8C13638A374D1673A8DDEB8E627DDD9C |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 4 |
| Overall | 25% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-13 12:52:43 UTC |
| Last Seen | 2026-08-30 20:53:56 UTC |
| Profile Built | 2026-08-30 21:02:05 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 27 |
Full dossier details are available via our API.