## INTELLIGENCE BRIEFING: 146.56.145.191
Classification: MODERATE RISK
Date: Current Intelligence Cycle
Scope: Full Profile Assessment
---
EXECUTIVE SUMMARY
IP address 146.56.145.191 belongs to ORACLE CORPORATION (ASN 31898) with a moderate overall risk score of 50. No active threat indicators, blacklist entries, or known campaign associations detected. The IP is classified as a firewalled Oracle Cloud infrastructure endpoint with no exposed services.
---
OWNERSHIP AND INFRASTRUCTURE
- Organization: ORACLE CORPORATION - network administrator
- Netname: ORACLECORP
- ASN: 31898
- CIDR Block: 146.56.0.0/17
- RIR: ARIN
- Network Role: Oracle Cloud Provider
GEOLOCATION DATA
- Country: South Korea (KR)
- City: Seoul
- Timezone: Asia/Tokyo
- Consensus: True (1 source)
- Note: Historical signals show geolocation variance between KR and JP, indicating multi-region routing or CDN characteristics
THREAT INDICATORS
- Risk Score: 50 (Moderate)
- Abuse Confidence Score: Not applicable
- Blacklist Count: 0
- Known Attacker: False
- Tor Exit Node: False
- Spam Source: False
- Known Campaigns: None
- Threat Feeds: None
NETWORK SERVICES
- Open Ports: None detected
- TLS Certificate: Not detected
- HTTP Banner: Not detected
- Service Classification: Firewalled / No Services
- DNS Records: No PTR hostnames, no forward resolution
CONTROL PLANE DATA
- Operator Score: 0.1304 (Minimal)
- BGP Prefix: 146.56.128.0/18
- Route Stability: False
- DNSBL Listed: 2 of 8 total lists
- DNSSEC: Valid
- Threat Persistence: 0 days (not persistently malicious)
---
OBSERVATION HISTORY
Total Observations: 11 signals
Recent activity (July 30, 2026) includes:
- ASN attribution: AS31898 (Oracle Corporation)
- Geolocation signals: Seoul, KR (confidence 0.50)
- Operator score: Minimal (0.1304)
- Ownership confirmation: Oracle Corporation
- Threat signals: None detected
Temporal Analysis: No persistent malicious behavior observed. Ownership changes: 0. Threat observation count: 0.
---
NETWORK RELATIONSHIPS
- Same Network Associations: ORACLECORP (2 relationships)
- External Links: None detected (no subnets, hostnames, organizations, or certificates)
---
NEIGHBORHOOD ANALYSIS
Subnet: 146.56.145.191/24
- Neighbor Count: 1 (146.56.145.147)
- Neighbor Risk Score: 25 (Low-Medium)
- Abuse Density: 0
- Classification: Low risk neighborhood
- Threat Siblings: 0
---
RECOMMENDATIONS FOR SOC ANALYSTS
1. BLOCKING: No immediate blocking recommended. IP represents legitimate Oracle Cloud infrastructure.
2. MONITORING: Monitor for service changes. Current profile shows no open ports, but cloud infrastructure can change rapidly.
3. WHITELIST CONSIDERATION: If this IP was flagged as suspicious, it may require investigation into false positive indicators. The Oracle Cloud context suggests this is infrastructure, not malicious.
4. GEOLINE VARIANCE: Note the KR/JP geolocation inconsistency. This is typical for cloud provider multi-region deployments and does not indicate spoofing.
5. DNSBL REVIEW: Two DNSBL listings detected. Investigate specific blacklist reasons if this IP was previously flagged by receiving mail systems.
---
ACTIONABLE FIREWALL RULES
No specific firewall rules generated. Standard Oracle Cloud infrastructure traffic patterns apply. If the IP was previously blocked, review the block reason against this current profile showing minimal operator score and no active threats.
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | ORACLE CORPORATION - network administrator |
| ASN | AS31898 |
| Network Name | ORACLECORP |
| CIDR Block | 146.56.0.0/17 |
| RIR | ARIN |
| Country | JP |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 2/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | โ |
| 8443 | https-alt | tcp | โ |
| Closed Ports | 22, 25, 80, 3389, 8080 (2 open / 7 scanned) | ||
| Server | AkamaiGHost |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | apps.mzstatic.comapi.music.apple.comconfiguration.apple.comradio-services.itunes.apple.comapi.videos.apple.comis3-ssl.mzstatic.comapi.podcasts.apple.coma5.mzstatic.comapi.edu.apple.comaccertify.mzstatic.com |
| Valid From | 2026-07-02T21:15:31+00:00 |
| Valid Until | 2027-01-07T19:46:05+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 188 days |
| Serial Number | 5EA9A0814EC260A592E0AFCC067CDF7A |
| Thumbprint | FC3FADE5E351D11D5BA6E3FF257AC262A40FD9A0 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 21% | 2 | 2 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Mixed Signals (68%) โ 2 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ TLS certificate claims US but primary geo says KR
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 22:49:37 UTC |
| Last Seen | 2026-08-13 06:43:52 UTC |
| Profile Built | 2026-08-13 00:10:07 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 26 |
Full dossier details are available via our API.