IPDebrief

165.227.193.76

IP Intelligence Dossier
Your IP: 216.73.217.135
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

INTELLIGENCE BRIEFING: IP 165.227.193.76

Date: 2026-06-21

Classification: LOW RISK / MONITORING REQUIRED

---

**EXECUTIVE SUMMARY**

IP 165.227.193.76 is a DigitalOcean cloud compute instance (ASN 14061) located in North Bergen, NJ. The IP resolves to hostname prod-boron-nyc1-72.do.binaryedge.ninja, indicating association with BinaryEdge infrastructure. Current risk assessment is LOW (score: 25), but historical data shows intermittent blacklist listings requiring monitoring.

---

**INFRASTRUCTURE PROFILE**

---

**THREAT ASSESSMENT**

MetricValue
**Risk Score**25 (Low Risk)
**Abuse Confidence**Not assessed
**Blacklist Count**0 (current)
**DNSBL Lists**8 total, 1 listed (high severity)
**Is Tor Exit**No
**Known Campaign**None
**Threat Persistence**0 days

---

**OBSERVATION HISTORY**

- SSH service detected on port 22

- Historical DNS blacklist listings (8 lists, 1 active with high severity)

- Geolocation validation failures (RTT 18ms vs. minimum possible 119.3ms for claimed 5,963km distance)

- Multiple signal types: subnet abuse, port scanning, DNS lookups, geo inference

---

**RELATIONSHIP ANALYSIS**

---

**NEIGHBORHOOD CONTEXT**

---

**SOC ACTIONABLE RECOMMENDATIONS**

IMMEDIATE ACTIONS:

1. Monitor Blacklist Status - Historical data shows intermittent DNSBL listings. Monitor for re-listing.

2. SSH Traffic Analysis - Active SSH service detected. Review inbound SSH traffic for anomalous patterns.

3. GeoValidation - Location claims appear invalid (RTT anomaly). Do not trust geolocation for threat correlation.

FIREWALL RULES (iptables):

```bash

# Allow established connections, block new SSH from high-risk sources

iptables -A INPUT -p tcp --dport 22 -m state --state ESTABLISHED,RELATED -j ACCEPT

# Block new SSH connections (optional - assess business need)

iptables -A INPUT -p tcp --dport 22 -m state --state NEW -j DROP

```

MONITORING PARAMETERS:

---

**CONCLUSION**

This IP represents a cloud infrastructure asset with low current threat indicators but requires continued monitoring due to historical blacklist activity and geolocation inconsistencies. The BinaryEdge hostname association suggests legitimate threat intelligence infrastructure usage, but the active SSH service and subnet-level threat presence warrant SOC attention. Maintain baseline monitoring and investigate any blacklist re-listings immediately.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionNJ
CityNorth Bergen
Timezoneβ€”
Latitude40.80
Longitude-74.02

🏒 Ownership & Registration

OrganizationDigitalOcean, LLC
ASNAS14061
Network NameDIGITALOCEAN-165-227-0-0
CIDR Block165.227.0.0/16
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRprod-boron-nyc1-72.do.binaryedge.ninja
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesprod-boron-nyc1-72.do.binaryedge.ninja

πŸ” DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeSingle-Service Host
Network TierTier 3 β€” Basic operator with some routing infrastructure
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
35%
23
routing
13%
11
services
19%
22
ownership
27%
23
reputation
22%
13
geolocation
35%
23
Overall25%1015
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-06-04 00:31:29 UTC
Last Seen2026-06-29 13:10:28 UTC
Profile Built2026-06-29 13:23:49 UTC
Data FreshnessLive
Signal Types23
Total Observations24
πŸ” 23 signal types Β· 24 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.