IPDebrief

167.234.221.222

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING: 167.234.221.222/32

Classification: Oracle Cloud Infrastructure - Moderate Risk

Risk Score: 50

Report Date: Analysis based on available intelligence

---

## OWNERSHIP & NETWORK IDENTIFICATION

The target IP 167.234.221.222 is owned by Oracle Corporation (ASN 31898, ORACLE-4), located within the CIDR block 167.234.128.0/17. Geographic attribution places the IP in San Jose, California, United States. The infrastructure operates on Oracle Cloud Compute infrastructure, classified as a single-service host with hosting capabilities enabled.

Key Identifiers:

---

## THREAT PROFILE

The IP demonstrates moderate risk characteristics with a score of 50. No direct threat indicators were observed, and the IP is not classified as a known attacker, spam source, or Tor exit node. Blacklist enumeration returned zero counts.

Control Plane Assessment:

---

## NETWORK ROLE & SERVICES

Active service enumeration revealed SSH access on port 22 (OpenSSH 9.6p1 Ubuntu-3ubuntu13.18). No TLS certificates, HTTP services, or email authentication mechanisms (SPF, DMARC) were detected. The system exhibits cloud-based hosting characteristics without CDN, VPN, proxy, or mobile carrier associations.

---

## OBSERVATION HISTORY (16 TOTAL OBSERVATIONS)

Historical signal analysis from 2026-07-30 indicates consistent classification as "clean" with zero abuse density and no inherited risk from the subnet. Recent observations maintain stable threat persistence metrics with no evidence of persistent malicious activity.

Notable Anomalies:

---

## NEIGHBORHOOD ANALYSIS

The /24 subnet (167.234.221.222/24) demonstrates clean characteristics:

No neighboring IPs exhibit malicious behavior, supporting the assessment of this as isolated cloud infrastructure.

---

## RELATIONSHIP GRAPH

Entity relationships exclusively link to ORACLE-4 network identifiers, confirming the IP operates within Oracle's cloud infrastructure ecosystem. No external organizational or certificate-based relationships detected.

---

## RECOMMENDED ACTIONS

Current Risk Assessment: The system recommends blocking actions despite moderate risk scoring. This recommendation is probabilistic and should be evaluated against operational context.

Recommended Firewall Rules:

```

iptables: iptables -A INPUT -s 167.234.221.222 -j DROP

nftables: nft add rule inet filter input ip saddr 167.234.221.222 drop

nginx: deny 167.234.221.222;

pfSense: 167.234.221.222/32

Cloudflare WAF: Block with expression "ip.src eq 167.234.221.222"

AWS WAF: Addresses 167.234.221.222/32

```

Analysis Note: Oracle Cloud infrastructure IPs can be legitimate. Blocking should be justified by additional corroborating evidence before implementation. The absence of threat indicators and clean neighborhood classification suggests this may be legitimate cloud hosting requiring no action.

---

## INTELLIGENCE SUMMARY

IP 167.234.221.222 is a moderate-risk Oracle Cloud Compute address with no active threat indicators. While the system's risk scoring recommends blocking, the IP's clean neighborhood classification and lack of direct threat evidence warrant careful evaluation before enforcement of restrictive firewall rules. SOC teams should monitor for activity escalation while maintaining operational flexibility for legitimate cloud infrastructure operations.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionCalifornia
CitySan Jose
Timezoneβ€”
Latitude37.24
Longitude-121.79

🏒 Ownership & Registration

OrganizationOracle Corporation
ASNAS31898
Network NameORACLE-4
CIDR Block167.234.128.0/17
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeSingle-Service Host
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
35%
23
routing
13%
11
services
19%
22
ownership
27%
23
reputation
15%
12
geolocation
27%
23
Overall23%1014
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-29 22:49:46 UTC
Last Seen2026-08-13 06:44:03 UTC
Profile Built2026-08-13 00:19:39 UTC
Data FreshnessLive
Signal Types18
Total Observations20
πŸ” 18 signal types Β· 20 observations collected
This report is generated from 18+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.