# IP Intelligence Briefing: 193.123.245.198/32
## Executive Summary
IP address 193.123.245.198 was classified as Moderate Risk (risk score: 40) during analysis on 2026-06-17. The IP is registered to Oracle Corporation (ASN 31898) and operates within Oracle Cloud infrastructure. No open services were detected, and the address is not flagged as a known attacker, Tor exit node, or spam source.
## Technical Profile
Ownership & Infrastructure
- Organization: Oracle Corporation
- ASN: AS31898
- Network Role: Cloud Compute / Hosting infrastructure
- CIDR Block: 193.123.224.0/19
Geolocation
- Country: US (with inconsistent geolocation consensus)
- City: Seoul, KR (per AlienVault OTX)
- Geoconsensus: Not unified across sources
Network Classification
- Cloud Provider: Oracle Cloud
- Infrastructure Type: CloudCompute
- Connection Type: Firewalled / No Services Detected
- DNS Resolution: Not confirmed forward-resolvable
- Open Ports: None detected
## Threat Indicators
Current Threat Status
- Blacklist Count: 0 (current profile)
- Known Campaigns: None
- Is Known Attacker: No
- Is Spammer: No
- Abuse Confidence Score: Not available
Signal History
- Total Observations: 19 (as of 2026-06-17)
- Threat Persistence: 0 days
- Not Persistently Malicious
- Recent observations indicate 8 DNSBL listings with 2 currently active
- Maximum severity observed: High
- Control plane shows route instability (non-MoAS)
## Network Context
Subnet Analysis (193.123.245.0/24)
- Abuse Density: Low (1)
- Classification: Mostly clean
- Total Siblings: 1 active
- Inherited Risk: 2
- High/Medium/Low Risk Neighbors: 0
Relationships
- 25 identified relationships, all pointing to network identifier OC-195
- Indicates placement within Oracle's cloud infrastructure ecosystem
## Risk Assessment
The IP presents moderate risk primarily due to:
1. Cloud hosting infrastructure designation
2. DNSBL listings (8 total lists)
3. Geolocation consensus inconsistencies
4. Route instability in control plane data
However, no direct threat indicators were observed (no known attacks, campaigns, or spam activity). The IP operates within Oracle Cloud infrastructure, which may explain the moderate risk classification.
## Recommended Actions
Firewall Rules
- `iptables -A INPUT -s 193.123.245.198 -j DROP`
- `nft add rule inet filter input ip saddr 193.123.245.198 drop`
- `nginx deny 193.123.245.198;`
- `pfsense: 193.123.245.198/32`
Cloud Security
- Cloudflare WAF: Block IP with expression `ip.src eq 193.123.245.198`
- AWS WAF: Add address `193.123.245.198/32` to rule group
Mitigation Notes
These rules are probabilistic and should be combined with other signals before taking action. The IP's moderate risk score warrants monitoring but does not indicate confirmed malicious activity.
---
*Intelligence generated from IPDebrief platform. Data current as of 2026-06-17.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Oracle Corporation |
| ASN | AS31898 |
| Network Name | β |
| CIDR Block | β |
| RIR | RIPE |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 20% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:04 UTC |
| Last Seen | 2026-06-27 02:32:01 UTC |
| Profile Built | 2026-06-27 20:38:59 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 23 |
Full dossier details are available via our API.