# IP INTELLIGENCE BRIEFING: 64.225.99.103/32
Classification: Cloud Infrastructure - Low Risk
Date: June 2026
Analyst: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
IP 64.225.99.103 is a low-risk cloud compute address hosted by DigitalOcean, LLC (AS14061) in Frankfurt am Main, Germany. The IP exhibits minimal threat indicators with a risk score of 25/100. No active malicious campaigns, known attacker associations, or spam source activity detected. The address operates in a mostly-clean subnet environment with limited abuse density.
---
## OWNERSHIP & INFRASTRUCTURE
| Attribute | Value |
|---|---|
| **Organization** | DigitalOcean, LLC |
| **ASN** | 14061 |
| **Network** | DIGITALOCEAN-64-225-0-0 |
| **CIDR Block** | 64.225.0.0/17 |
| **Infrastructure Type** | CloudCompute |
| **Location** | Frankfurt am Main, Germany (DE) |
| **Region** | HE |
| **Timezone** | Europe/Berlin |
---
## THREAT ASSESSMENT
| Metric | Value | Assessment |
|---|---|---|
| **Risk Score** | 25 | Low Risk |
| **Abuse Confidence Score** | N/A | No active abuse |
| **Threat Indicators** | None | Clean |
| **Blacklist Count** | 0 | Not blacklisted |
| **DNSBL Listed** | 1 of 8 | Minimal presence |
| **Tor Exit Node** | No | False |
| **Known Attacker** | No | False |
| **Spam Source** | No | False |
Key Findings:
- No open services detected on the address (firewalled configuration)
- No TLS certificates or HTTP services identified
- Not associated with any known threat campaigns
- No correlation to IP reputation feeds
---
## OBSERVATION HISTORY
Total Observations: 19
Threat Persistence: 0 days
Ownership Stability: Stable (0 changes)
Recent signal observations indicate consistent operator scoring at 0.1304 (Minimal). Geolocation signals have remained stable with Frankfurt, Germany coordinates throughout the observation window. No escalation in threat severity observed.
---
## SUBNET ANALYSIS (64.225.99.0/24)
| Metric | Value |
|---|---|
| **Abuse Density** | 0.5 |
| **Classification** | Mostly Clean |
| **Total Siblings** | 2 |
| **Active Siblings** | 0 |
| **Inherited Risk** | 2 |
Neighbor IP: 64.225.99.186
- Risk Score: 25
- Authority Score: 50
- Status: Low Risk
The /24 subnet exhibits low overall abuse density with the target IP and its single neighbor both registering low-risk profiles.
---
## NETWORK CLASSIFICATION
| Classification | Status |
|---|---|
| **Provider** | DigitalOcean (Cloud) |
| **CDN** | No |
| **VPN** | No |
| **Proxy** | No |
| **Tor** | No |
| **Hosting** | Yes |
| **Mobile** | No |
| **Residential** | No |
| **Bogon** | No |
| **Anycast** | No |
---
## RECOMMENDED ACTIONS
Firewall/Security Actions:
- No blocking required. IP represents legitimate cloud infrastructure.
- Standard cloud security policies apply.
- Monitor for any behavioral anomalies consistent with the IP's historical profile.
SOC Guidance:
- Treat as low-priority traffic source
- No immediate threat mitigation actions required
- Continue standard monitoring procedures
- No whitelisting required unless this IP is a known legitimate sender
---
## CONCLUSION
IP 64.225.99.103 represents standard DigitalOcean cloud infrastructure with no active threat indicators. The address maintains a clean reputation profile with minimal DNSBL presence and stable geolocation data. No defensive action required beyond routine monitoring.
Status: โ CLEAR FOR NORMAL OPERATIONS
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-64-225-0-0 |
| CIDR Block | 64.225.0.0/17 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 19% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 19% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Fresh
| First Seen | 2026-06-05 07:06:00 UTC |
| Last Seen | 2026-06-21 12:15:38 UTC |
| Profile Built | 2026-06-21 15:24:07 UTC |
| Data Freshness | Fresh |
| Signal Types | 18 |
| Total Observations | 19 |
Full dossier details are available via our API.