IP INTELLIGENCE BRIEFING
Target: 168.110.104.103/32
Classification: Low Risk
Date of Analysis: 2026-07-30
---
EXECUTIVE SUMMARY
IP address 168.110.104.103 was assessed as low risk with an overall risk score of 25. The address is provisioned by Oracle Cloud infrastructure with minimal operator score (0.1304). No active network services were detected, and the system appears to be firewalled with no open ports.
---
TECHNICAL PROFILE
Infrastructure Classification:
- Provider: Oracle Cloud
- Network Classification: Unknown infrastructure type
- Connection Type: Not classified
- Cloud Service: Not confirmed (cloud flag: false)
- Proxy/VPN/Tor: All flags negative
- Bogon: Not classified
Geolocation:
- Country: South Korea (KR)
- Region: Gangwon-do
- City: Chuncheon
- Coordinates: 37.8897°N, 127.736°E
- Data Source: MaxMind GeoLite2-City
Control Plane:
- Origin ASN: 31898
- BGP Prefix: 168.110.96.0/19
- Route Stability: Not stable (isRouteStable: false)
- DNSSEC: Valid
- DNSBL Listings: 1 of 8 total lists
---
NETWORK SERVICES
No active services were identified:
- Open Ports: None detected
- TLS Certificates: Not present
- HTTP Title: Not present
- Server Banner: Not present
- Fingerprint Status: No HTTP/2, no HSTS, no CSP detected
---
THREAT INDICATORS
Current Threat Assessment:
- Abuse Confidence Score: Not provided
- Is Known Attacker: False
- Is Spam Source: False
- Is Tor Exit Node: False
- Blacklist Count: 0
- Threat Feeds: Empty
Behavioral Analysis:
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: 0
- Is Persistently Malicious: False
- Is Active Attacker: False
Campaign Indicators:
- Campaign Likelihood: Not assessed
- Certificate Matches: 0
- Banner Matches: 0
- Correlated IPs: 0
---
OBSERVATION HISTORY
Nine observations were recorded over the analysis period. Recent activity includes:
- SSH protocol detected: SSH-2.0-OpenSSH_8.4p1 Debian-5+deb11u7
- Provider classification: Oracle Cloud (confidence: 0.90)
- Geolocation confirmed for South Korea (confidence: 0.70)
- Operator score maintained at minimal (0.1304, confidence: 0.30)
Temporal analysis indicates:
- Ownership Changes: 0
- Average Ownership Days: Not calculated
- Threat Persistence Days: 0
- Threat Observation Count: 0
---
RELATIONSHIP ANALYSIS
No relationships were identified in the relationship graph. The IP has no links to:
- Related subnets: None
- Associated hostnames: None
- Connected organizations: None
- Linked certificates: None
---
NEIGHBORHOOD ANALYSIS
Subnet analysis for 168.110.104.103/24:
- Neighbor Count: 0
- Total Siblings: 0
- Active Siblings: 0
- Threat Siblings: 0
- Abuse Density: 0
No neighboring IP addresses were discovered, and the subnet shows zero abuse density.
---
RECOMMENDED ACTIONS
Based on the risk profile and threat indicators, the following security posture is appropriate:
1. Traffic Treatment: Monitor for inbound connections; no immediate block required based on low-risk classification.
2. Firewall Rules: No specific firewall rules recommended beyond standard network segmentation.
3. WAF Configuration: No WAF rules required; no web services detected.
4. Threat Hunting: No immediate threat hunting actions warranted.
---
INTELLIGENCE CONCLUSION
IP 168.110.104.103 is an Oracle Cloud provisioned address with a low-risk profile. The system appears to be properly secured with no open services. No threat indicators were detected, and the IP shows no association with known malicious infrastructure. The address can be treated as benign with standard monitoring procedures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Oracle Corporation |
| ASN | AS31898 |
| Network Name | ORACLE-4 |
| CIDR Block | 168.110.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.4p1 Debian-5+deb11u7 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 23% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 22:49:47 UTC |
| Last Seen | 2026-08-13 06:44:03 UTC |
| Profile Built | 2026-08-13 00:16:33 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 18 |
Full dossier details are available via our API.