INTELLIGENCE BRIEFING: IP 165.227.193.76
Date: 2026-06-21
Classification: LOW RISK / MONITORING REQUIRED
---
**EXECUTIVE SUMMARY**
IP 165.227.193.76 is a DigitalOcean cloud compute instance (ASN 14061) located in North Bergen, NJ. The IP resolves to hostname prod-boron-nyc1-72.do.binaryedge.ninja, indicating association with BinaryEdge infrastructure. Current risk assessment is LOW (score: 25), but historical data shows intermittent blacklist listings requiring monitoring.
---
**INFRASTRUCTURE PROFILE**
- Organization: DigitalOcean, LLC
- ASN: 14061 (DIGITALOCEAN-165-227-0-0)
- CIDR Block: 165.227.0.0/16
- Geolocation: US, New Jersey (North Bergen)
- Service Type: Cloud Compute (Single-Service Host)
- Open Ports: TCP/22 (SSH - OpenSSH 8.9p1 Ubuntu-3ubuntu0.15)
- TLS/HTTP: None detected
---
**THREAT ASSESSMENT**
| Metric | Value |
|---|---|
| **Risk Score** | 25 (Low Risk) |
| **Abuse Confidence** | Not assessed |
| **Blacklist Count** | 0 (current) |
| **DNSBL Lists** | 8 total, 1 listed (high severity) |
| **Is Tor Exit** | No |
| **Known Campaign** | None |
| **Threat Persistence** | 0 days |
---
**OBSERVATION HISTORY**
- Total Observations: 22
- Recent Signals: 2026-06-21
- Subnet Classification: Mostly clean (abuse density: 1)
- Threat Siblings: 1 in /24 subnet
- Notable Findings:
- SSH service detected on port 22
- Historical DNS blacklist listings (8 lists, 1 active with high severity)
- Geolocation validation failures (RTT 18ms vs. minimum possible 119.3ms for claimed 5,963km distance)
- Multiple signal types: subnet abuse, port scanning, DNS lookups, geo inference
---
**RELATIONSHIP ANALYSIS**
- DNS Associations: prod-boron-nyc1-72.do.binaryedge.ninja (repeated 29x)
- Network Relations: Same network (DIGITALOCEAN-165-227-0-0) - 29 entries
- Control Plane: BGP prefix 165.227.192.0/20 (route stability: false)
- Operator Score: 0.2609 (Basic)
---
**NEIGHBORHOOD CONTEXT**
- Subnet: 165.227.193.76/24
- Abuse Density: 0 (neighbor scan)
- Risk Distribution: 0 high/medium/low (neighbor scan)
- Note: Profile indicates 1 threat sibling in subnet
---
**SOC ACTIONABLE RECOMMENDATIONS**
IMMEDIATE ACTIONS:
1. Monitor Blacklist Status - Historical data shows intermittent DNSBL listings. Monitor for re-listing.
2. SSH Traffic Analysis - Active SSH service detected. Review inbound SSH traffic for anomalous patterns.
3. GeoValidation - Location claims appear invalid (RTT anomaly). Do not trust geolocation for threat correlation.
FIREWALL RULES (iptables):
```bash
# Allow established connections, block new SSH from high-risk sources
iptables -A INPUT -p tcp --dport 22 -m state --state ESTABLISHED,RELATED -j ACCEPT
# Block new SSH connections (optional - assess business need)
iptables -A INPUT -p tcp --dport 22 -m state --state NEW -j DROP
```
MONITORING PARAMETERS:
- Track DNSBL re-listing status
- Monitor for new port/service openings
- Alert on subnet-level abuse density changes
- Verify hostname resolution patterns
---
**CONCLUSION**
This IP represents a cloud infrastructure asset with low current threat indicators but requires continued monitoring due to historical blacklist activity and geolocation inconsistencies. The BinaryEdge hostname association suggests legitimate threat intelligence infrastructure usage, but the active SSH service and subnet-level threat presence warrant SOC attention. Maintain baseline monitoring and investigate any blacklist re-listings immediately.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-165-227-0-0 |
| CIDR Block | 165.227.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | prod-boron-nyc1-72.do.binaryedge.ninja |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | prod-boron-nyc1-72.do.binaryedge.ninja |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 25% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-04 00:31:29 UTC |
| Last Seen | 2026-06-29 13:10:28 UTC |
| Profile Built | 2026-06-29 13:23:49 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.