# IP Intelligence Briefing: 64.225.65.182/32
Classification: Low Risk / Cloud Infrastructure
Date: 2026-06-21
## Executive Summary
IP 64.225.65.182 is a DigitalOcean cloud infrastructure endpoint located in Amsterdam, Netherlands. The IP presents a low threat profile with a risk score of 25/100 and no active malicious indicators. No blacklist entries, no Tor/VPN/proxy characteristics, and no open services detected.
## Network Ownership and Geolocation
- Provider: DigitalOcean, LLC (ASN 14061)
- Network Block: 64.225.0.0/17 (CIDR: DIGITALOCEAN-64-225-0-0)
- Location: Amsterdam, Netherlands (NL)
- Coordinates: 52.13°N, 5.29°E
- Infrastructure Type: Cloud Compute (Cloud-hosted)
## Threat Assessment
- Risk Score: 25 (Low Risk)
- Blacklist Count: 0
- Abuse Confidence Score: None reported
- Known Campaigns: None
- Threat Indicators: None detected
- DNSBL Listings: 1 of 8 lists (minimal operator score: 0.1304)
## Technical Profile
- Open Ports: None
- TLS Certificates: None
- Forward Resolution: Not confirmed
- PTR Hostnames: None
- Service Purpose: Firewalled / No Services
- Connection Type: Cloud infrastructure
## Behavioral Observations
- Cloud Status: Yes (confirmed cloud infrastructure)
- Tor Exit: No
- VPN/Proxy: No
- Residential/Mobile: No
- Anycast: No
- Bogon: No
## Neighborhood Analysis (/24 Subnet)
- Subnet: 64.225.65.0/24
- Abuse Density: 0.5 (moderate)
- Classification: Mostly Clean
- Active Siblings: 2
- Threat Siblings: 1
- Neighbor IP: 64.225.65.47 (Risk Score: 25, Authority Score: 50)
## Historical Signals (19 Observations)
Recent observations indicate:
- Consistent DigitalOcean cloud infrastructure classification
- Geolocation data from Alienvault-OTX (Amsterdam)
- Stability in provider ownership (0 ownership changes)
- No persistent malicious behavior detected
- Operator label: "Minimal"
## Network Relationships
All 14 relationship records point to the same network: DIGITALOCEAN-64-225-0-0, indicating this IP is a standard endpoint within the DigitalOcean 64.225.0.0/17 block.
## Recommended Actions
- Allow/Permit: Traffic to/from this IP is permitted for general cloud infrastructure communication
- Monitor: No immediate blocking required
- Context: This IP is legitimate cloud hosting infrastructure with no active threat indicators
## SOC Notes
This IP address represents standard DigitalOcean cloud infrastructure. The low risk score, absence of blacklist entries, and "mostly_clean" neighborhood classification indicate normal operational traffic. No firewall rules or blocking actions are recommended at this time.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-64-225-0-0 |
| CIDR Block | 64.225.0.0/17 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | n8n.rustemvinograd.com |
| Valid From | 2026-06-20T09:24:56+00:00 |
| Valid Until | 2026-09-18T09:24:55+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 055DD6BC4316D15A03C71B0534DDBF61E523 |
| Thumbprint | 071EE001A5652F5AE0BEA4921874BAB290CABA29 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-01 23:54:58 UTC |
| Last Seen | 2026-06-21 08:08:55 UTC |
| Profile Built | 2026-06-21 08:40:42 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.