IP Intelligence Briefing: 129.213.142.121
Date: 2026-06-12
---
**1. Core Profile**
- Risk Score: High (80/100)
- Ownership: Oracle Public Cloud (ASN 31898, ARIN-regulated)
- Geolocation: Ashburn, VA, US (latitude 39.83, longitude -98.58)
- Network Role: CloudCompute (Oracle Cloud infrastructure)
- Threat Indicators: No direct malicious activity detected.
- DNSSEC: Validated.
- BGP: Route unstable (likely due to Oracleβs network configuration).
---
**2. Threat Observations**
- DNSBL Listings:
- Listed on 4/8 DNSBLs (e.g., Spamhaus, OpenDNS).
- Risk Implication: Potential spam or abuse risk, though no confirmed malicious campaigns.
- Geolocation Accuracy: Low confidence (2,500 km accuracy radius).
- Route Stability: Unstable BGP route (12 hops, 28.8 ms RTT).
---
**3. Network Relationships**
- Shared Network: Part of Oracleβs OC-195 network (129.213.0.0/16).
- Subnet: 129.213.142.0/24 (no active neighbors detected).
---
**4. Historical Trends**
- Recent Activity (Last 30 Days):
- No persistent threats or ownership changes.
- DNSBL listings detected in June 2026.
- Geolocation data consistent with Oracleβs infrastructure.
---
**5. Recommendations**
- Monitor DNSBL Listings: Investigate why this Oracle IP is listed on spam-focused blacklists.
- Network Stability: Verify BGP route stability with Oracleβs network team.
- Access Control: Consider restricting access to this IP if itβs not a known internal asset.
- Geolocation Verification: Cross-check with internal geolocation tools due to low confidence.
---
Conclusion:
This IP is part of Oracleβs cloud infrastructure and shows no direct malicious activity. However, its DNSBL listings and unstable BGP route suggest potential misconfiguration or abuse. SOC teams should monitor for anomalous behavior and validate DNSBL entries with Oracle.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Oracle Public Cloud |
| ASN | AS31898 |
| Network Name | OC-195 |
| CIDR Block | 129.213.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| 8080 | http-alt | tcp | β |
| Closed Ports | 25, 80, 443, 3389, 8443 (2 open / 7 scanned) | ||
| Server | Jetty(9.4.53.v20231009) |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_7.4 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 42% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 26% | 10 | 17 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Fresh
| First Seen | 2026-06-04 00:31:13 UTC |
| Last Seen | 2026-06-26 18:10:35 UTC |
| Profile Built | 2026-06-21 22:06:03 UTC |
| Data Freshness | Fresh |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.