## IP Intelligence Briefing: 170.64.220.63
Executive Summary
IP 170.64.220.63 is a DigitalOcean cloud infrastructure endpoint located in Sydney, Australia with an overall risk score of 25 (Low Risk). The IP operates within the DIGITALOCEAN-170-64-128-0 network block (170.64.128.0/17) and shows no active threat indicators, though it appears on one DNS blacklist among eight queried sources.
Technical Profile
Network Attribution:
- Organization: DigitalOcean, LLC (ASN 14061)
- Network Block: 170.64.128.0/17
- Geolocation: Sydney, New South Wales, Australia (AU)
- Infrastructure Type: Cloud Compute / Hosting
- DNS Resolution: No PTR hostnames, no forward resolution
Service Status:
- Open Ports: None detected (firewalled/no services exposed)
- TLS/HTTP: No certificates, no HTTP title or server banners
- Infrastructure Role: Cloud provider hosting environment
Threat Assessment
Current Risk Indicators:
- Risk Score: 25 (Low Risk classification)
- Reputation: Low Risk
- Blacklist Status: Listed on 1 of 8 DNSBL sources
- Known Attackers/Spam Sources: No
- Tor Exit Node: No
- Active Campaigns: None detected
Temporal Analysis:
- Threat Observation Count: 1
- Threat Persistence Days: 0
- Status: Not persistently malicious
- Ownership Changes: 0
Network Context
Subnet Neighborhood (170.64.220.63/24):
- Subnet Classification: Mostly clean
- Abuse Density: 1 (profile) / 0 (neighbor analysis)
- Threat Siblings: 1 detected
- Total Siblings: 1 active
- Risk Distribution: No high or medium risk neighbors identified
Relationship Graph:
- 11 relationships identified, all pointing to same network (DIGITALOCEAN-170-64-128-0)
- Indicates standard cloud infrastructure network topology
Control Plane Observations
- Route Stability: False (instability detected)
- DNSSEC Valid: True
- DNSBL Listed: 1 of 8 lists
- Operator Score: 0.1304 (Minimal)
- Route Changes (30d): 0
- MOAS Status: False
Historical Signal Timeline
- June 15, 2026: Operator score 0.1304 (Minimal), full dimensional coverage across 6 signal dimensions
- June 10, 2026: Geolocation AU confirmed (35% confidence), subnet classified as "mostly_clean"
- Campaign Analysis: None correlated, zero certificate matches
Operational Recommendations
Recommended Actions:
1. No blocking required โ IP maintains low-risk classification with no active threat indicators
2. Monitor DNSBL status โ IP appears on 1 of 8 DNS blacklist sources; verify if legitimate listing or false positive
3. Route stability monitoring โ Control plane shows route instability flags; monitor for infrastructure changes
4. Baseline behavior โ Cloud hosting environment with no exposed services; typical for infrastructure-as-a-service deployments
Firewall Rules:
- No specific blocking rules recommended based on current risk profile
- Standard cloud provider egress rules apply
- Consider allow-listing if IP appears in known legitimate service patterns
Conclusion
IP 170.64.220.63 represents a standard DigitalOcean cloud infrastructure endpoint with low risk characteristics. The single DNSBL listing warrants verification but does not indicate malicious activity. The subnet shows minimal threat presence with one threat sibling identified. No immediate defensive action required beyond standard cloud provider monitoring practices.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-170-64-128-0 |
| CIDR Block | 170.64.128.0/17 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 34% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-25 12:41:47 UTC |
| Last Seen | 2026-06-29 01:34:13 UTC |
| Profile Built | 2026-06-29 07:37:00 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.