# IPDEBRIEF THREAT INTELLIGENCE BRIEFING
Target: 64.226.72.196/32
Date: 2026-07-29
Classification: LOW RISK
---
## EXECUTIVE SUMMARY
IP 64.226.72.196 is a DigitalOcean cloud infrastructure address with a low-risk reputation profile. No malicious indicators, blacklist listings, or threat campaigns detected. Recommended monitoring level: Standard. No immediate firewall blocking required.
---
## INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| **Organization** | DigitalOcean |
| **ASN** | 14061 |
| **BGP Prefix** | 64.226.64.0/20 |
| **Location** | Frankfurt am Main, Hesse, DE |
| **Infrastructure Type** | Cloud Provider |
| **Service Purpose** | Firewalled / No Services |
---
## THREAT ASSESSMENT
Risk Score: 0 (Low Risk)
Abuse Confidence: Not Applicable
Blacklist Status: Clean (0 listings)
Known Campaigns: None
Threat Indicators:
- Not a Tor exit node
- Not a known attacker
- Not a spam source
- No malicious activity observed
Network Role:
- Cloud infrastructure: Yes
- CDN: No
- Proxy: No
- VPN: No
- Hosting: No
---
## SERVICE & PORT ANALYSIS
- Open Ports: None detected
- TLS Certificates: None
- HTTP Title: None
- DNS Records: No PTR hostnames, no forward resolution
- Email Authentication: SPF/DMARC not configured
---
## OBSERVATION HISTORY
Total Observations: 10
Observation Window: Recent (2026-07-29)
Signal Trends:
- Cloud infrastructure classification stable (DigitalOcean)
- Geolocation consistently reported as DE (Frankfurt)
- No changes in risk profile over observation period
- No new threat signals detected
---
## NEIGHBORHOOD ANALYSIS
Subnet: 64.226.72.0/24
Abuse Density: 0 (Clean)
Threat Siblings: 0
Active Siblings: 0
No malicious activity detected in immediate /24 neighborhood.
---
## RELATIONSHIP GRAPH
No related entities discovered (no associated hostnames, organizations, or certificates).
---
## RECOMMENDED ACTIONS
Security Posture: No action required
Firewall Rules: None recommended
Monitoring Level: Standard network traffic monitoring
Note: IP classified as cloud infrastructure with no exposed services. Traffic patterns should be evaluated based on legitimate DigitalOcean customer usage profiles.
---
## ANALYST NOTES
This IP represents routine DigitalOcean cloud infrastructure. The lack of open ports, clean reputation, and absence of threat indicators suggest benign cloud hosting. No correlation with known malicious campaigns or attacker infrastructure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-64-226-64-0 |
| CIDR Block | 64.226.64.0/18 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
๐ TLS Certificate
| SANs | trade.ebull.io |
| Valid From | 2026-07-29T07:47:20+00:00 |
| Valid Until | 2026-10-27T07:47:19+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 050EE2730A61BC3FB0C876AAA328029EB1BF |
| Thumbprint | FBE3CDF0EB68CCDD983AB4A419F8486377F82B92 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 35% | 2 | 4 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 29% | 10 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 07:16:30 UTC |
| Last Seen | 2026-08-12 16:45:17 UTC |
| Profile Built | 2026-08-12 16:59:02 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.