Threat Intelligence Briefing: IP 170.64.135.39/32
Source IP Summary:
1. Observation History:
- The IP address 170.64.135.39/32, belonging to the IP range 170.64.0.0/10, is designated as a Shared Address Space (SAS) by the Internet Assigned Numbers Authority (IANA). This range is reserved for carrier-grade NAT (CGN) deployments and is not assigned for public internet use.
2. Typical Use:
- The 170.64.0.0/10 block is commonly used by Internet Service Providers (ISPs) to allocate private IP addresses to end-users behind NAT devices. These addresses are not routable on the global internet, meaning they are intended for internal use within a network.
3. Neighborhood Data:
- The immediate neighborhood of this IP consists of other addresses within the 170.64.0.0/10 range. These addresses are part of the same NAT deployment and are not associated with publicly accessible services.
4. Relationships:
- There are no known direct relationships with malicious actors or networks. The IP address itself is not linked to any known malicious activity or threat actors due to its usage within carrier-grade NAT environments.
5. Potential Indicators:
- If observed in network traffic logs, this IP could indicate internal network traffic or misconfigured network equipment attempting to communicate over the internet. It may also appear in logs due to NAT traversal techniques or misconfigurations where internal network traffic is mistakenly routed externally.
Actionable Recommendations:
- Investigate Network Configurations:
- Verify if the IP address appears in internal network traffic logs. Ensure that network equipment is correctly configured to prevent internal traffic from being mistakenly directed to the internet.
- Monitor for Anomalous Patterns:
- Look for unusual patterns of communication involving the 170.64.0.0/10 range that may suggest misconfigurations or attempts to bypass NAT restrictions.
- Review NAT Policies:
- Ensure that NAT policies are correctly implemented to prevent internal addresses from being exposed to external networks.
- Educate Network Users:
- Inform network users about the nature of these IP addresses to prevent unnecessary concern or reports of suspicious activity when these addresses appear in network logs.
This intelligence briefing provides a comprehensive overview of the IP address 170.64.135.39/32, highlighting its typical use, potential indicators of misconfiguration, and actionable recommendations for network defenders.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 19% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-20 23:39:03 UTC |
| Last Seen | 2026-06-28 12:52:40 UTC |
| Profile Built | 2026-06-29 06:58:43 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 20 |
Full dossier details are available via our API.