# IPDebrief Intelligence Briefing
Target: 64.225.98.114/32
Date: 2026-06-15
Classification: Low Risk / Cloud Infrastructure
---
## EXECUTIVE SUMMARY
IP address 64.225.98.114 is a low-risk cloud compute endpoint hosted on DigitalOcean infrastructure in Frankfurt, Germany. The IP exhibits typical hosting characteristics with minimal threat indicators. Current risk score is 25, with no active threat associations or known campaign involvement. The IP is listed on 1 of 8 DNSBLs with high severity, though overall subnet abuse density remains at 0.
---
## INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| **IP Address** | 64.225.98.114/32 |
| **Organization** | DigitalOcean, LLC (ASN 14061) |
| **Network** | DIGITALOCEAN-64-225-0-0 /64.225.0.0/17 |
| **Location** | Frankfurt am Main, Hesse, Germany (DE) |
| **Infrastructure Type** | Cloud Compute / Multi-Service Host |
| **Reputation Score** | 25 (Low Risk) |
| **DNSBL Status** | Listed on 1 of 8 lists |
---
## NETWORK SERVICES
The endpoint exposes two services:
- Port 22 (TCP/SSH): OpenSSH 8.9p1 Ubuntu-3ubuntu0.15
- Port 8080 (TCP/HTTP-Alt): Alt HTTP service (no HTTP title or TLS certificate detected)
No reverse DNS PTR records exist for this address. Forward DNS resolution is not confirmed.
---
## THREAT ASSESSMENT
Current Threat Indicators: None
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Known Campaigns: None
- Abuse Confidence Score: Not available
- Blacklist Count: 0 (despite 1 DNSBL listing)
Risk Breakdown:
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
- Risk Label: Low Risk
---
## NEIGHBORHOOD ANALYSIS
Subnet: 64.225.98.114/24
- Abuse Density: 0 (Clean)
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 0
- Classification: Clean
The immediate /24 subnet shows no abuse indicators and no correlated threat activity. All sibling IPs are classified as non-malicious.
---
## OBSERVATION HISTORY
Sixteen observations were recorded, most recent on 2026-06-15. Key historical findings:
- DNSBL Detection: High-severity listing detected on 2026-06-15 23:42:41 UTC
- Subnet Classification: Consistently "clean" across all observations
- Abuse Density: Remained at 0 throughout observation period
- Correlated IPs: 0 correlated IPs detected
- Campaign Likelihood: None
- Route Stability: Flagged as unstable (route changes in last 30 days: 0)
---
## RELATIONSHIP ANALYSIS
All 11 relationship entries indicate "Same Network" association with DIGITALOCEAN-64-225-0-0. This is expected for cloud infrastructure and indicates the IP is part of the broader DigitalOcean network fabric.
---
## RECOMMENDED ACTIONS
Firewall Rules: No specific blocking recommended based on current risk profile.
Monitoring Recommendations:
1. Monitor for escalation in DNSBL listings
2. Track route stability changes
3. Review SSH port access patterns if this IP is not in your organization's allowlist
Contextual Notes:
- This IP operates on DigitalOcean cloud infrastructure (common for legitimate hosting)
- Low risk score (25) combined with clean subnet classification supports continued operation
- The single DNSBL listing appears to be an isolated incident rather than pattern-based abuse
---
## INTELLIGENCE CONFIDENCE
Data Sources: 6
Overall Confidence: 0.2479
Data Sufficiency: 1 of 6 dimensions covered
Assessment: This IP represents low-risk cloud infrastructure with no active threat indicators. No immediate defensive actions required unless this IP is not expected in your traffic baseline.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-64-225-0-0 |
| CIDR Block | 64.225.0.0/17 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| 8080 | http-alt | tcp | โ |
| Closed Ports | 25, 80, 443, 3389, 8443 (2 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 18% | 1 | 2 |
| geolocation | 34% | 2 | 3 |
| Overall | 21% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-25 12:42:59 UTC |
| Last Seen | 2026-06-29 01:49:20 UTC |
| Profile Built | 2026-06-29 07:50:57 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 20 |
Full dossier details are available via our API.