# IP INTELLIGENCE BRIEFING
Target: 170.64.231.224/32
Classification: Low Risk
Date: Current Analysis
Prepared By: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
IP address 170.64.231.224 is a low-risk cloud compute resource hosted by DigitalOcean, LLC in Sydney, Australia. The address operates as a web server with standard HTTP/HTTPS services and SSH access. No active threat indicators were detected. The IP is classified as "Low Risk" with a risk score of 25/100.
---
## OWNERSHIP AND GEOLOCATION
| Attribute | Value |
|---|---|
| **ASN** | 14061 (DigitalOcean, LLC) |
| **Organization** | DigitalOcean, LLC |
| **Country** | Australia (AU) |
| **Region** | New South Wales (NSW) |
| **City** | Sydney |
| **BGP Prefix** | 170.64.224.0/20 |
| **Infrastructure Type** | CloudCompute |
---
## NETWORK SERVICES
Open Ports:
- 80/tcp (HTTP)
- 443/tcp (HTTPS)
- 22/tcp (SSH - OpenSSH 9.6p1 Ubuntu)
Server Information:
- Web Server: Caddy
- TLS Certificate: None detected
- Server Banner: Caddy
---
## THREAT ASSESSMENT
Risk Profile:
- Overall Risk Score: 25/100 (Low Risk)
- Abuse Confidence Score: Not available
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
Control Plane Indicators:
- DNSBL Listed: 1 of 8 total lists
- Operator Score: 0.1304 (Minimal)
- RPKI State: Not available
- Route Stability: False
Threat Indicators: None detected
---
## OBSERVATION HISTORY
Total Signals Observed: 18
Recent Activity (June 20, 2026):
- Cloud infrastructure classification confirmed (DigitalOcean)
- Geographic location inferred: Australia (confidence 0.35)
- Connection attempts observed with intermittent failures
- Subnet abuse density classified as "mostly_clean"
Temporal Analysis:
- Threat Persistence Days: 0
- Is Persistently Malicious: No
- Ownership Changes: 0
---
## NEIGHBORHOOD ANALYSIS
Subnet: 170.64.231.224/24
- Abuse Density: 0 (neighborhood tool) / 1 (profile)
- Classification: mostly_clean
- Total Siblings: 1
- Threat Siblings: 1
---
## RELATIONSHIP GRAPH
Total Relationships: 24
- All relationships indicate membership in DIGITALOCEAN-170-64-128-0 network block
- No external associations detected (hostnames, organizations, certificates)
---
## SECURITY RECOMMENDATIONS
Action Status: No specific actions required
Assessment: The IP presents minimal security risk. Standard defensive posture appropriate for cloud infrastructure. No immediate firewall rules or blocking recommendations.
---
## ANALYST NOTES
This IP address represents typical cloud hosting infrastructure with no malicious activity detected. The single DNSBL listing may warrant monitoring but does not indicate active abuse. The IP is part of a stable DigitalOcean network block with low neighborhood abuse density. Routine monitoring recommended; no escalation required at this time.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Caddy |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 40% | 2 | 3 |
| Overall | 26% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-24 12:34:02 UTC |
| Last Seen | 2026-06-29 00:03:28 UTC |
| Profile Built | 2026-06-29 06:05:36 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.