IP Intelligence Briefing: 129.225.172.187/32
Ownership and Classification
The IP address 129.225.172.187 belongs to Oracle Corporation (AS31898, ORACLE-4), registered within the 129.225.0.0/16 CIDR block. The IP is classified as Oracle Cloud infrastructure with a moderate risk score of 50. Geolocation data places the address in Osaka, Japan.
Network Risk Profile
The IP exhibits an open TCP port 3389 (RDP), an anomalous exposure for Oracle Cloud infrastructure. The address is listed on 2 of 8 DNSBLs checked. Control plane analysis shows the IP is not stable, with route changes recorded within the 30-day period. The operator score is 0.3043, classified as "Basic."
Observation History
Twenty-one observations were recorded, with the most recent on 2026-08-13. The IP demonstrates stable ownership with zero recent transfers over 3 and 5 years. Abuse density for the /24 subnet (129.225.172.187/24) is 0, with a "clean" classification. No threat siblings were detected in the neighborhood. The IP is not persistently malicious.
Relationships
All seven relationship entries link to the ORACLE-4 network, confirming the IP resides within Oracle's corporate network infrastructure.
Threat Indicators
No active threat indicators were identified. The IP is not flagged as a Tor exit node, known attacker, or spam source. No associated threat campaigns were matched.
Assessment and Recommendations
While the IP shows stable ownership and a clean neighborhood profile, the exposed RDP port (3389) represents a potential attack surface. For Oracle Cloud environments, RDP access is typically restricted behind management interfaces. The exposure warrants verification to determine whether this is intentional administrative access or unintended exposure. SOC teams should monitor for inbound connections to port 3389 and correlate with threat intelligence feeds. No immediate blocking is recommended given the moderate risk score and lack of active malicious activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Oracle Corporation |
| ASN | AS31898 |
| Network Name | ORACLE-4 |
| CIDR Block | 129.225.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | โ |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 24% | 2 | 2 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 28% | 11 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (65%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-06 06:39:28 UTC |
| Last Seen | 2026-08-13 08:36:23 UTC |
| Profile Built | 2026-08-13 08:41:38 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.