INTELLIGENCE BRIEFING: 64.225.65.47
Classification: LOW RISK | Provider: DigitalOcean, LLC (AS14061) | Location: Amsterdam, Netherlands
---
OVERVIEW
The target IP 64.225.65.47 is a low-risk cloud compute infrastructure host operated by DigitalOcean, LLC (ASN 14061). The IP is registered within the DIGITALOCEAN-64-225-0-0 CIDR block (64.225.0.0/17) and operates as a single-service host in Amsterdam, Netherlands. Current risk assessment scores 25/100 (Low Risk) with no active threat indicators or campaign associations.
NETWORK INFRASTRUCTURE
- Provider: DigitalOcean CloudCompute (Infrastructure Type: Cloud)
- Geolocation: Amsterdam, NH, Netherlands (52.13°N, 5.29°E)
- Infrastructure Classification: Cloud Hosting Environment
- Open Services: SSH (Port 22/tcp) - OpenSSH 8.9p1 Ubuntu-3ubuntu0.15
- DNSBL Status: Listed on 1 of 8 monitoring lists
- Route Stability: Not route stable (route changes observed in last 30 days)
THREAT ASSESSMENT
- Risk Score: 25/100 (Low Risk)
- Abuse Confidence: Not elevated
- Threat Indicators: None detected
- Campaign Associations: None identified
- Known Attacker Status: Not flagged
- Tor Exit Node: Not detected
- Spam Source: Not flagged
CONTROLS PLANE
- BGP Prefix: 64.225.64.0/20
- RPKI Status: Validated
- DNSSEC: Valid
- Operator Risk Score: 0.1304 (Minimal)
- Threat Persistence: None observed
SUBNET ANALYSIS (64.225.65.0/24)
- Abuse Density: 0.5 (Moderate)
- Classification: Mostly Clean
- Total Siblings: 2
- Active Siblings: 2
- Threat Siblings: 1
- Neighbor IP: 64.225.65.182 (Risk Score: 25, Authority Score: 50)
OBSERVATION HISTORY
Seventeen signals observed across the monitoring period. Most recent observations (2026-06-16) confirm:
- Geographic consistency: Amsterdam, Netherlands
- Control plane signals: Minimal operator risk
- Neighborhood classification: Mostly clean with low inherited risk
- No persistent malicious behavior detected
RELATIONSHIP GRAPH
Nine relationships identified, all mapping to the same network block (DIGITALOCEAN-64-225-0-0). The IP shows no associations with external threat actors, hostnames, organizations beyond the provider, or certificates.
---
RECOMMENDATION
No immediate blocking action required. The IP exhibits standard cloud compute infrastructure behavior with minimal risk indicators. Monitor for changes in threat indicators or campaign associations. Standard logging and traffic inspection applicable for all traffic to/from this cloud IP range.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-64-225-0-0 |
| CIDR Block | 64.225.0.0/17 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 19% | 2 | 2 |
| Overall | 21% | 10 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-03 06:16:58 UTC |
| Last Seen | 2026-06-21 10:03:20 UTC |
| Profile Built | 2026-06-21 10:20:46 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 22 |
Full dossier details are available via our API.