# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 165.232.189.48/32
Classification: Low Risk Infrastructure IP
Date: Current Analysis Cycle
---
## Executive Summary
IP 165.232.189.48 is a cloud-compute infrastructure endpoint operated by DigitalOcean, LLC (ASN 14061) located in Bengaluru, India. The IP presents a low-risk profile (risk score: 25) with no active threat indicators or malicious campaign associations. Current classification indicates "mostly_clean" subnet status with minimal abuse density.
---
## Infrastructure Profile
Ownership:
- Organization: DigitalOcean, LLC
- ASN: 14061
- CIDR Block: 165.232.32.0/19
- Network Name: DIGITALOCEAN-165-232-32-0
Geolocation:
- Country: India (IN)
- City: Bengaluru
- RIR: ARIN
Network Role:
- Infrastructure Type: Cloud Compute
- Connection Type: Web Server
- DNSSEC Valid: Yes
---
## Service & Host Configuration
Open Ports:
- 80/tcp (HTTP)
- 443/tcp (HTTPS)
- 22/tcp (SSH - OpenSSH 9.6p1 Ubuntu)
Server Fingerprint:
- Web Server: nginx/1.24.0 (Ubuntu)
- HTTP Status: 404 (Not Found)
- TLS Certificate: Let's Encrypt (CN=shrinidhi.patternsync.com)
DNS Analysis:
- Forward Resolution: Failed
- PTR Hostnames: None
- Hosted Domains: 0
---
## Threat Indicators Assessment
Active Threat Status:
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0
Campaign Association:
- Campaign Likelihood: None
- CERT Matches: 0
- Correlated IPs: 0
Control Plane:
- Operator Score: 0.1304 (Minimal)
- Route Stability: Unstable
- DNSBL Listed Count: 1
- DNSBL Total Lists: 8
---
## Neighborhood Analysis
Subnet: 165.232.189.48/24
- Abuse Density: 0 (Low)
- Classification: Mostly Clean
- Active Siblings: 2
- Threat Siblings: 2
Neighbor IP Analysis:
- 165.232.189.117: Risk Score 25 (Low)
---
## Temporal Observations
Historical Signal Count: 25 observations
- Recent Activity: 2026-06-29
- Threat Persistence Days: 0
- Ownership Changes: 0
- Persistently Malicious: No
Key Historical Signals:
- Network classification maintained as "mostly_clean"
- HTTP fingerprinting consistent (nginx 1.24.0)
- No significant risk profile changes observed
---
## Recommended Actions
Immediate: No firewall rules or blocking actions recommended based on current risk profile.
Monitoring: Continue standard monitoring. IP demonstrates stable infrastructure behavior with no emerging threat signals.
Context: This IP serves as a legitimate cloud hosting endpoint. The presence of a Let's Encrypt certificate for shrinidhi.patternsync.com indicates active web services. SSH access is configured, which is typical for cloud infrastructure.
---
Assessment: Low-risk cloud infrastructure IP with no actionable threat indicators. Standard monitoring protocols apply.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-165-232-32-0 |
| CIDR Block | 165.232.32.0/19 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | shrinidhi.patternsync.com |
| Valid From | 2026-06-17T04:04:26+00:00 |
| Valid Until | 2026-09-15T04:04:25+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 057D25D8A4113BE5CEB5800CB62AF9AE5578 |
| Thumbprint | 0CA86D43029F9C8FE9C54E6A9F974367EEEB7124 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 27% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 24% | 2 | 3 |
| Overall | 23% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-30 00:19:38 UTC |
| Last Seen | 2026-06-29 06:56:09 UTC |
| Profile Built | 2026-06-29 07:03:18 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.