# INTELLIGENCE BRIEFING: 64.225.107.170
Classification: LOW RISK โข Date: Current Assessment
---
## EXECUTIVE SUMMARY
IP address 64.225.107.170 is a cloud infrastructure endpoint operating within DigitalOcean's Frankfurt, Germany data center. The endpoint exhibits minimal risk characteristics with no active malicious indicators. Assessment indicates standard cloud hosting infrastructure with no evidence of command-and-control, spam generation, or known campaign participation.
---
## OWNERSHIP & INFRASTRUCTURE
Organization: DigitalOcean, LLC (ASN 14061)
Network: 64.225.96.0/20
Location: Frankfurt am Main, DE (Europe/Berlin timezone)
Infrastructure Type: CloudCompute (Single-Service Host)
Geolocation Confidence: 98% (600km accuracy radius)
The IP resides within DigitalOcean's controlled cloud infrastructure, operating under BGP prefix 64.225.96.0/20. Control plane analysis confirms stable routing with no anomalies detected.
---
## THREAT ASSESSMENT
Overall Risk Score: 25/100 (Low)
Abuse Confidence Score: Not applicable (no active threats)
Blacklist Status: Listed on 1 of 8 DNSBLs (minimal impact)
Threat Indicators:
- Is Known Attacker: No
- Is Tor Exit Node: No
- Is VPN/Proxy: No
- Is Spam Source: No
- Active Campaigns: None detected
---
## NETWORK BEHAVIOR
Open Services:
- Port 22/tcp: SSH (OpenSSH_9.6p1 Ubuntu-3ubuntu13.16)
- HTTP Status: 303 (Redirect)
Network Role Classification: Cloud hosting infrastructure with single-service deployment pattern. No CDN, anycast, or residential characteristics observed.
---
## NEIGHBORHOOD ANALYSIS
Subnet: 64.225.107.170/24
Abuse Density: 0.0 (Clean)
Classification: Clean
Sibling IPs:
- 64.225.107.141: Risk Score 25 (Low)
- 64.225.107.145: Risk Score 0 (Clean)
Subnet contains 3 total sibling IPs with 2 actively monitored. No threat siblings detected within the /24 block.
---
## OBSERVATION HISTORY
Total Observations: 21 signals tracked
Recent Activity (June 2026):
- 2026-06-28: Minimal operator score, 0 threat signals
- 2026-06-20: Confirmed cloud infrastructure deployment in DE
- No ownership changes recorded
- Threat persistence days: 0
- Is Persistently Malicious: No
The IP demonstrates consistent cloud hosting behavior with no escalation in threat profile over the observation window.
---
## RELATIONSHIP GRAPH
Identified Relationships: 17
- All relationships map to DIGITALOCEAN-64-225-0-0 network segment
- No external organizational or certificate associations beyond standard cloud infrastructure
- No correlated malicious IPs identified
---
## RECOMMENDATIONS
Security Posture: Standard cloud infrastructure risk profile. No immediate remediation required.
Monitoring: Continue standard network logging. No specific firewall rules generated due to low risk classification.
Action Items: None. The IP exhibits normal cloud hosting behavior consistent with DigitalOcean infrastructure deployments.
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | nginx/1.18.0 |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 03:36:48 UTC |
| Last Seen | 2026-06-28 08:37:10 UTC |
| Profile Built | 2026-06-29 02:40:51 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.