# IP Intelligence Briefing: 144.22.165.206
## Executive Summary
IP 144.22.165.206 is a moderate-risk address (Score: 55) assigned to Oracle Corporation's cloud infrastructure in São Paulo, Brazil. The endpoint hosts a web service for mogatelecom.com.br with no evidence of active malicious activity. Minor reputation concerns stem from DNSBL listings on 3 of 8 threat feeds.
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **Organization** | Oracle Corporation (ASN 31898) |
| **Network Block** | 144.22.128.0/17 |
| **Geolocation** | São Paulo, Brazil |
| **Infrastructure Type** | Oracle Cloud |
| **Classification** | Web Server |
## Network Services
- Port 80/443 (TCP): HTTP/HTTPS services operational
- Port 22 (TCP): SSH service (OpenSSH_8.4p1 Debian)
- TLS Certificate: CloudFlare Origin SSL for mogatelecom.com.br
- Server Software: Apache/2.4.67 (Debian)
## Threat Assessment
- Risk Score: 55/100 (Moderate Risk)
- Abuse Confidence: Not elevated
- Known Attacker: No
- Tor Exit Node: No
- DNSBL Status: Listed on 3 of 8 threat feeds (operator score: 0.1304)
- Threat Persistence: None detected (0 threat observation days)
## Historical Activity
Observation history from August 2026 indicates stable behavior with consistent HTTP/HTTPS responses. No escalation in risk posture or emergence of new threat indicators over the monitoring period.
## Neighborhood Analysis
- Subnet Abuse Density: 0% (Clean)
- Neighboring Threats: 0 high/medium risk IPs detected in /24
- Correlated IPs: None identified
## Relationship Graph
The IP maintains network-level relationships solely to the Oracle 144.22.128.0/17 block. No associations with external malicious entities or command-and-control infrastructure.
## Recommended Actions
1. Monitor: Continue passive monitoring given the moderate risk score and DNSBL listings
2. Contextualize: The IP serves legitimate cloud infrastructure; false-positive risk exists
3. Threat Intel: No immediate blocking required unless specific IOCs match
## Conclusion
144.22.165.206 represents Oracle Cloud infrastructure hosting a commercial web service. The moderate risk classification is primarily driven by DNSBL listings rather than confirmed malicious activity. The subnet shows clean neighborhood behavior with no inherited risk. This IP may appear in threat feeds due to false positives or unrelated reputation factors.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Oracle Corporation |
| ASN | AS31898 |
| Network Name | 144.22.128.0 - 144.22.255.255 |
| CIDR Block | 144.22.128.0/17 |
| RIR | ARIN |
| Country | BR |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Apache/2.4.67 (Debian) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.4p1 Debian-5+deb11u7 |
๐ TLS Certificate
| SANs | *.mogatelecom.com.brmogatelecom.com.br |
| Valid From | 2024-07-31T17:45:00+00:00 |
| Valid Until | 2039-07-28T17:45:00+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 5475 days |
| Serial Number | 5874B93AA2DE60D3062AF96F55C284E9D3B34921 |
| Thumbprint | 987D7F966C9AD37037AAEF34762D6D1E4F30246E |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 35% | 2 | 3 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 29% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-03 23:38:28 UTC |
| Last Seen | 2026-08-13 06:43:51 UTC |
| Profile Built | 2026-08-13 05:47:49 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.