IPDebrief

165.245.229.123

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IPDEBRIEF INTELLIGENCE BRIEFING

Target: 165.245.229.123/32

Classification: Cloud Compute Infrastructure

Risk Level: Low Risk (Score: 25)

Date: Intelligence generated from live data

---

## EXECUTIVE SUMMARY

IP 165.245.229.123 is a cloud computing infrastructure address hosted on DigitalOcean, LLC's network infrastructure. The IP demonstrates low-risk characteristics with minimal operator scores and no active threat indicators. While the IP shows minimal service exposure, historical data indicates transient blacklist activity that has since resolved. The asset should be monitored but does not currently warrant immediate blocking or elevated alerting.

---

## OWNERSHIP AND INFRASTRUCTURE

AttributeValue
ASN14061
OrganizationDigitalOcean, LLC
CIDR Block165.245.224.0/20
Network RoleCloud Compute / Hosting
Infrastructure TypeCloudCompute
LocationNew York, NY, US
GeoValidationDNSSEC Valid (ICMP blocked - unable to validate)

---

## THREAT INTELLIGENCE

Current Risk Profile

Historical Observations (23 total)

Threat Indicators

---

## NETWORK AND CONTROL PLANE

MetricValue
BGP Prefix165.245.224.0/20
Route Changes (30d)0
Route StabilityFalse
MoASFalse
RPKI StateNull
IRR ConsistencyN/A
DNSSEC ValidYes
DNSBL Listed0 (current)
Operator Score0.1304 (Minimal)

---

## NETWORK NEIGHBORHOOD

Subnet: 165.245.229.0/24

The /24 subnet exhibits minimal abuse density with inherited risk of 2. Neighborhood context does not indicate coordinated malicious activity.

---

## SERVICES AND FINGERPRINTING

AttributeValue
Open PortsNone detected
Server Typenginx
HTTP Status200
HTTP/2Yes
HSTSYes
CSPNo
Referrer PolicyYes
Permissions PolicyNo
TTFB133ms

No open services or ports detected. The IP responds to HTTP requests with nginx serving content. No TLS certificates or email authentication records present.

---

## RELATIONSHIP ANALYSIS

---

## RECOMMENDED ACTIONS

Current Status: No immediate action required

The IP demonstrates standard cloud infrastructure behavior with no active threat indicators. Recommended approach:

1. Allow with Monitoring: Traffic may be permitted with standard logging

2. No Blocking Required: Current risk profile does not warrant firewall blocking

3. Historical Context: Previous blacklist activity has resolved; monitor for recurrence

4. Geographic Consistency: US-based origin aligns with declared geolocation

---

Assessment: This IP address represents legitimate cloud infrastructure on DigitalOcean's platform. While historical blacklist activity was observed, current telemetry shows minimal risk. No immediate defensive action is recommended beyond standard traffic logging and monitoring.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionNY
CityNew York
TimezoneAmerica/New_York
Latitude40.71
Longitude-74.01

🏒 Ownership & Registration

OrganizationDigitalOcean, LLC
ASNAS14061
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeSingle-Service Host
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Servernginx
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
24%
24
routing
8%
11
services
23%
23
ownership
20%
23
reputation
26%
13
geolocation
30%
23
Overall22%1017
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-07 23:03:51 UTC
Last Seen2026-06-27 01:21:16 UTC
Profile Built2026-06-28 01:13:03 UTC
Data FreshnessLive
Signal Types21
Total Observations28
πŸ” 21 signal types Β· 28 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.