IPDebrief

144.22.165.206

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 144.22.165.206

## Executive Summary

IP 144.22.165.206 is a moderate-risk address (Score: 55) assigned to Oracle Corporation's cloud infrastructure in São Paulo, Brazil. The endpoint hosts a web service for mogatelecom.com.br with no evidence of active malicious activity. Minor reputation concerns stem from DNSBL listings on 3 of 8 threat feeds.

## Infrastructure Profile

AttributeValue
**Organization**Oracle Corporation (ASN 31898)
**Network Block**144.22.128.0/17
**Geolocation**São Paulo, Brazil
**Infrastructure Type**Oracle Cloud
**Classification**Web Server

## Network Services

## Threat Assessment

## Historical Activity

Observation history from August 2026 indicates stable behavior with consistent HTTP/HTTPS responses. No escalation in risk posture or emergence of new threat indicators over the monitoring period.

## Neighborhood Analysis

## Relationship Graph

The IP maintains network-level relationships solely to the Oracle 144.22.128.0/17 block. No associations with external malicious entities or command-and-control infrastructure.

## Recommended Actions

1. Monitor: Continue passive monitoring given the moderate risk score and DNSBL listings

2. Contextualize: The IP serves legitimate cloud infrastructure; false-positive risk exists

3. Threat Intel: No immediate blocking required unless specific IOCs match

## Conclusion

144.22.165.206 represents Oracle Cloud infrastructure hosting a commercial web service. The moderate risk classification is primarily driven by DNSBL listings rather than confirmed malicious activity. The subnet shows clean neighborhood behavior with no inherited risk. This IP may appear in threat feeds due to false positives or unrelated reputation factors.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ง๐Ÿ‡ท Brazil
RegionSão Paulo
CitySão Paulo
Timezoneโ€”
Latitude-23.55
Longitude-46.64

๐Ÿข Ownership & Registration

OrganizationOracle Corporation
ASNAS31898
Network Name144.22.128.0 - 144.22.255.255
CIDR Block144.22.128.0/17
RIRARIN
CountryBR
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
ServerApache/2.4.67 (Debian)
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_8.4p1 Debian-5+deb11u7

๐Ÿ” TLS Certificate

๐Ÿ”’
CN=CloudFlare Origin Certificate, OU=CloudFlare Origin CA, O="CloudFlare, Inc."
Issued by S=California, L=San Francisco, OU=CloudFlare Origin SSL Certificate Authority, O="CloudFlare, Inc.", C=US
Self-signed: No
SANs*.mogatelecom.com.brmogatelecom.com.br
Valid From2024-07-31T17:45:00+00:00
Valid Until2039-07-28T17:45:00+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period5475 days
Serial Number5874B93AA2DE60D3062AF96F55C284E9D3B34921
Thumbprint987D7F966C9AD37037AAEF34762D6D1E4F30246E

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
35%
23
routing
17%
11
services
35%
23
ownership
35%
23
reputation
17%
12
geolocation
35%
23
Overall29%1015
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Claimed geolocation contradicts RTT physics measurement

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-08-03 23:38:28 UTC
Last Seen2026-08-13 06:43:51 UTC
Profile Built2026-08-13 05:47:49 UTC
Data FreshnessLive
Signal Types20
Total Observations21
๐Ÿ” 20 signal types ยท 21 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.