IPDebrief

131.186.28.8

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 131.186.28.8/32

Classification: Low Risk Cloud Infrastructure

Report Date: Current

Status: Monitoring Recommended

---

## Executive Summary

IP address 131.186.28.8 is assigned to Oracle Public Cloud (ASN 31898) within the OC-195 network block. The IP maintains a low overall risk score of 25 with minimal provider and authority scores. The asset operates as cloud compute infrastructure with hosting capabilities and exhibits limited threat indicators.

---

## Network Profile

AttributeValue
**ASN**31898 (Oracle Public Cloud)
**Organization**Oracle Public Cloud
**Network**OC-195
**CIDR Block**131.186.0.0/16
**Infrastructure Type**CloudCompute
**Service Classification**Hosting
**Geolocation**US (Seoul region)
**Risk Score**25 (Low Risk)

---

## Threat Indicators

---

## Network Services

PortProtocolServiceBanner
22TCPSSHSSH-2.0-OpenSSH_10.3

No HTTP services detected. No TLS certificates observed.

---

## Historical Observation Analysis

Eighteen observation signals recorded over the monitoring period. Key temporal findings:

The IP exhibits stable ownership with no ownership changes observed. Threat observation count remains minimal (1 total), indicating limited malicious activity.

---

## Relationship Mapping

Seventeen network relationships identified, all pointing to OC-195 network designation. All relationships classified as "Same Network" type, indicating consistent network attribution within the Oracle Cloud infrastructure block.

---

## Neighborhood Assessment

Subnet: 131.186.28.8/24

Abuse Density: 0

Classification: Mostly Clean

Total Siblings: 1

Active Siblings: 1

Threat Siblings: 1

The /24 subnet demonstrates minimal abuse density with one active sibling IP address and one threat-associated sibling. No high or medium-risk neighbors detected.

---

## Recommended Actions

No specific firewall rules or mitigation recommendations generated at this time based on current risk profile. The IP maintains low-risk classification consistent with legitimate Oracle Cloud hosting infrastructure.

---

## Intelligence Narrative

The IP 131.186.28.8 operates within Oracle Public Cloud infrastructure and presents a low-risk profile (score 25). The asset functions as cloud compute hosting with SSH service exposure on port 22. Single DNSBL listing indicates minor reputation friction but does not indicate active malicious activity. Historical observations show consistent cloud infrastructure classification with stable ownership. The associated /24 subnet maintains clean abuse density metrics. No correlation to known threat campaigns or persistent malicious behavior.

SOC Recommendation: Monitor for service changes or risk score increases. No immediate blocking required. Include in cloud infrastructure baseline monitoring.

---

*Report generated from IPDebrief intelligence data. All findings derived from observed network signals and threat intelligence feeds.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionSeoul
CitySeoul
Timezoneβ€”
Latitude37.54
Longitude126.86

🏒 Ownership & Registration

OrganizationOracle Public Cloud
ASNAS31898
Network NameOC-195
CIDR Block131.186.0.0/16
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeSingle-Service Host
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_10.3

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
24
routing
13%
11
services
19%
22
ownership
27%
23
reputation
22%
13
geolocation
24%
23
Overall22%1016
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-28 23:50:43 UTC
Last Seen2026-06-29 05:56:14 UTC
Profile Built2026-06-29 05:58:38 UTC
Data FreshnessLive
Signal Types19
Total Observations19
πŸ” 19 signal types Β· 19 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.