# IP Intelligence Briefing: 64.225.103.125
## Executive Summary
Target 64.225.103.125 is a DigitalOcean cloud infrastructure IP in Frankfurt, Germany (DE) with a low-risk profile. The IP shows no open services, no open ports, and no active threat indicators. However, the surrounding subnet exhibits elevated activity requiring contextual monitoring.
## Network Profile
- Organization: DigitalOcean, LLC (ASN 14061)
- CIDR Block: 64.225.0.0/17
- Geolocation: Frankfurt am Main, Hesse, DE
- Infrastructure Type: CloudCompute (Public Cloud)
- Risk Score: 0 (Low Risk)
- Abuse Confidence Score: Not available
- Blacklist Count: 0
- DNSBL Status: Listed on 8 DNSBLs (8 total lists)
## Current Threat Assessment
The target IP shows no active threat indicators:
- No known attacker indicators
- No Tor exit node activity
- No spam source classification
- No associated threat campaigns
- No open ports or services detected (firewalled)
Classification: Firewalled / No Services
## Neighborhood Analysis
The /24 subnet (64.225.103.0/24) presents a mixed risk profile:
- Subnet Abuse Density: 0.5 (moderate)
- Inherited Risk Score: 2
- Active Siblings: 2 out of 2 total neighbors
- Threat Siblings: 1
Notable neighbors include:
- 64.225.103.194: Risk Score 40, Authority Score 50 (medium risk)
- 64.225.103.210: No scoring data available
## Historical Observations
Analysis of 21 observation records reveals:
- Threat Observation Count: 1
- Operator Score: 0.1304 (Minimal)
- DNSBL Listings: Consistent presence across 8 lists with severity classifications including high-severity entries
- Subnet Abuse Density: Varied over time (observed range 0.33-0.5)
- Classification: Predominantly "mostly_clean"
- Persistence: Not persistently malicious
## Routing & Control Plane
- Origin ASN: 14061 (DigitalOcean)
- BGP Prefix: 64.225.96.0/20
- Route Stability: False (route changes detected)
- MOAS Status: Not a most commonly announced subnet
- RPKI State: Not verified
- RTT Analysis: 105ms minimum, 111ms average (5 probe attempts)
## Recommended Actions
No immediate blocking or firewall actions recommended. The IP maintains a clean profile with no open services or active threat indicators. However, the following monitoring considerations apply:
1. Monitor Subnet Activity: One neighbor (64.225.103.194) shows medium risk activity; monitor for lateral correlation
2. DNSBL Context: Despite the target IP showing 0 blacklist count, 8 DNSBL lists reference the subnet; verify if this indicates subnet-level or IP-specific listing
3. Cloud Infrastructure Context: As a DigitalOcean cloud IP, traffic patterns should be evaluated against cloud abuse baselines rather than traditional hosting indicators
## Conclusion
IP 64.225.103.125 presents as a benign DigitalOcean cloud infrastructure endpoint with no direct threat indicators. The primary concern stems from the subnet-level activity, particularly the medium-risk neighbor at 64.225.103.194. SOC analysts should monitor for any activity correlation between the target and its neighbors, but no immediate containment or blocking actions are warranted based on current data.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-64-225-0-0 |
| CIDR Block | 64.225.0.0/17 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 4 |
| Overall | 27% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 22:50:47 UTC |
| Last Seen | 2026-08-13 00:19:32 UTC |
| Profile Built | 2026-08-13 00:29:13 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.