# IP Intelligence Briefing: 131.186.28.8/32
Classification: Low Risk Cloud Infrastructure
Report Date: Current
Status: Monitoring Recommended
---
## Executive Summary
IP address 131.186.28.8 is assigned to Oracle Public Cloud (ASN 31898) within the OC-195 network block. The IP maintains a low overall risk score of 25 with minimal provider and authority scores. The asset operates as cloud compute infrastructure with hosting capabilities and exhibits limited threat indicators.
---
## Network Profile
| Attribute | Value |
|---|---|
| **ASN** | 31898 (Oracle Public Cloud) |
| **Organization** | Oracle Public Cloud |
| **Network** | OC-195 |
| **CIDR Block** | 131.186.0.0/16 |
| **Infrastructure Type** | CloudCompute |
| **Service Classification** | Hosting |
| **Geolocation** | US (Seoul region) |
| **Risk Score** | 25 (Low Risk) |
---
## Threat Indicators
- Blacklist Status: Listed on 1 of 8 DNSBL feeds
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Known Campaigns: None identified
- Threat Persistence Days: 0
- Threat Observation Count: 1
---
## Network Services
| Port | Protocol | Service | Banner |
|---|---|---|---|
| 22 | TCP | SSH | SSH-2.0-OpenSSH_10.3 |
No HTTP services detected. No TLS certificates observed.
---
## Historical Observation Analysis
Eighteen observation signals recorded over the monitoring period. Key temporal findings:
- Classification Signal: Recent observations confirm cloud infrastructure status with 90% confidence
- Operator Score: 0.1304 (Minimal threat operator classification)
- DNS Security: DNSSEC validation active
- Port Scanning: SSH service detected on port 22
- Geolocation: US region consistently reported (confidence 0.35)
The IP exhibits stable ownership with no ownership changes observed. Threat observation count remains minimal (1 total), indicating limited malicious activity.
---
## Relationship Mapping
Seventeen network relationships identified, all pointing to OC-195 network designation. All relationships classified as "Same Network" type, indicating consistent network attribution within the Oracle Cloud infrastructure block.
---
## Neighborhood Assessment
Subnet: 131.186.28.8/24
Abuse Density: 0
Classification: Mostly Clean
Total Siblings: 1
Active Siblings: 1
Threat Siblings: 1
The /24 subnet demonstrates minimal abuse density with one active sibling IP address and one threat-associated sibling. No high or medium-risk neighbors detected.
---
## Recommended Actions
No specific firewall rules or mitigation recommendations generated at this time based on current risk profile. The IP maintains low-risk classification consistent with legitimate Oracle Cloud hosting infrastructure.
---
## Intelligence Narrative
The IP 131.186.28.8 operates within Oracle Public Cloud infrastructure and presents a low-risk profile (score 25). The asset functions as cloud compute hosting with SSH service exposure on port 22. Single DNSBL listing indicates minor reputation friction but does not indicate active malicious activity. Historical observations show consistent cloud infrastructure classification with stable ownership. The associated /24 subnet maintains clean abuse density metrics. No correlation to known threat campaigns or persistent malicious behavior.
SOC Recommendation: Monitor for service changes or risk score increases. No immediate blocking required. Include in cloud infrastructure baseline monitoring.
---
*Report generated from IPDebrief intelligence data. All findings derived from observed network signals and threat intelligence feeds.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Oracle Public Cloud |
| ASN | AS31898 |
| Network Name | OC-195 |
| CIDR Block | 131.186.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_10.3 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 24% | 2 | 3 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-28 23:50:43 UTC |
| Last Seen | 2026-06-29 05:56:14 UTC |
| Profile Built | 2026-06-29 05:58:38 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.