# IP INTELLIGENCE BRIEFING: 167.234.221.222/32
Classification: Oracle Cloud Infrastructure - Moderate Risk
Risk Score: 50
Report Date: Analysis based on available intelligence
---
## OWNERSHIP & NETWORK IDENTIFICATION
The target IP 167.234.221.222 is owned by Oracle Corporation (ASN 31898, ORACLE-4), located within the CIDR block 167.234.128.0/17. Geographic attribution places the IP in San Jose, California, United States. The infrastructure operates on Oracle Cloud Compute infrastructure, classified as a single-service host with hosting capabilities enabled.
Key Identifiers:
- Organization: Oracle Corporation
- ASN: 31898
- Network Name: ORACLE-4
- Infrastructure Type: CloudCompute
- Service Purpose: Single-Service Host
---
## THREAT PROFILE
The IP demonstrates moderate risk characteristics with a score of 50. No direct threat indicators were observed, and the IP is not classified as a known attacker, spam source, or Tor exit node. Blacklist enumeration returned zero counts.
Control Plane Assessment:
- BGP Prefix: 167.234.208.0/20
- Route Stability: Unstable
- DNSBL Listings: 2 out of 8 total lists
- Operator Score: 0.1304 (Minimal)
---
## NETWORK ROLE & SERVICES
Active service enumeration revealed SSH access on port 22 (OpenSSH 9.6p1 Ubuntu-3ubuntu13.18). No TLS certificates, HTTP services, or email authentication mechanisms (SPF, DMARC) were detected. The system exhibits cloud-based hosting characteristics without CDN, VPN, proxy, or mobile carrier associations.
---
## OBSERVATION HISTORY (16 TOTAL OBSERVATIONS)
Historical signal analysis from 2026-07-30 indicates consistent classification as "clean" with zero abuse density and no inherited risk from the subnet. Recent observations maintain stable threat persistence metrics with no evidence of persistent malicious activity.
Notable Anomalies:
- Geographic plausibility validation failed (GeoPlausible: false)
- RTT measurement of 86ms indicates distance discrepancy (reported 8866km from San Jose, minimum expected 177.3ms)
---
## NEIGHBORHOOD ANALYSIS
The /24 subnet (167.234.221.222/24) demonstrates clean characteristics:
- Abuse Density: 0
- Subnet Classification: Clean
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 0
No neighboring IPs exhibit malicious behavior, supporting the assessment of this as isolated cloud infrastructure.
---
## RELATIONSHIP GRAPH
Entity relationships exclusively link to ORACLE-4 network identifiers, confirming the IP operates within Oracle's cloud infrastructure ecosystem. No external organizational or certificate-based relationships detected.
---
## RECOMMENDED ACTIONS
Current Risk Assessment: The system recommends blocking actions despite moderate risk scoring. This recommendation is probabilistic and should be evaluated against operational context.
Recommended Firewall Rules:
```
iptables: iptables -A INPUT -s 167.234.221.222 -j DROP
nftables: nft add rule inet filter input ip saddr 167.234.221.222 drop
nginx: deny 167.234.221.222;
pfSense: 167.234.221.222/32
Cloudflare WAF: Block with expression "ip.src eq 167.234.221.222"
AWS WAF: Addresses 167.234.221.222/32
```
Analysis Note: Oracle Cloud infrastructure IPs can be legitimate. Blocking should be justified by additional corroborating evidence before implementation. The absence of threat indicators and clean neighborhood classification suggests this may be legitimate cloud hosting requiring no action.
---
## INTELLIGENCE SUMMARY
IP 167.234.221.222 is a moderate-risk Oracle Cloud Compute address with no active threat indicators. While the system's risk scoring recommends blocking, the IP's clean neighborhood classification and lack of direct threat evidence warrant careful evaluation before enforcement of restrictive firewall rules. SOC teams should monitor for activity escalation while maintaining operational flexibility for legitimate cloud infrastructure operations.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Oracle Corporation |
| ASN | AS31898 |
| Network Name | ORACLE-4 |
| CIDR Block | 167.234.128.0/17 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 23% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-29 22:49:46 UTC |
| Last Seen | 2026-08-13 06:44:03 UTC |
| Profile Built | 2026-08-13 00:19:39 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 20 |
Full dossier details are available via our API.