Threat Intelligence Briefing for IP 213.35.120.133/32
Date: 2026-06-12
---
**1. IP Profile**
- Risk Score: Moderate (50/100)
- Ownership: Oracle Cloud (AS31898, RIPE)
- Geolocation: Registered to "GB" (United Kingdom), inferred as Loyang (potential placeholder). Latitude/Longitude unspecified.
- Network Role: Oracle infrastructure (firewalled, no active services detected).
- Threat Indicators: Clean; no malicious indicators, spam, or known attacker associations.
---
**2. Observation History**
- Risk Trends: Minimal risk over 30 days; no persistent malicious activity.
- Geolocation Consensus: Inferred via DNSSEC and routing data, but lacks precise city/latitude/longitude.
- Subnet Analysis:
- 213.35.120.133/24 classified as "clean" with 0% abuse density.
- Neighbors: 3 IPs in subnet (213.35.120.0/24), 2 active (risk scores: 40, 25).
---
**3. Relationships**
- Linked Entities:
- Oracle Cloud network (AS31898, "SE-ORACLE-SE-20000113").
- No hostnames, domains, or certificates associated.
- Control Plane:
- BGP prefix: 213.35.96.0/19.
- DNSSEC valid; no CAA records.
---
**4. Neighborhood Analysis**
- Subnet (213.35.120.0/24):
- Abuse Density: 0% (clean).
- Neighbors:
- 213.35.120.167: Moderate risk (40/100).
- 213.35.120.253: Low risk (25/100).
- No malicious siblings detected.
---
**5. Recommendations**
- Monitor Subnet: Track 213.35.120.167 (moderate risk) for anomalies.
- Verify Geolocation: Investigate "Loyang" discrepancy; confirm if itβs a data error or intentional obfuscation.
- Firewall Actions: Consider allowing Oracle Cloud traffic (AS31898) but block IPs with elevated risk scores in the subnet.
- Reputation Checks: Validate DNSSEC and CAA records for Oracleβs network.
---
Conclusion: This IP is part of Oracle Cloud infrastructure with no current malicious activity. However, the subnet contains lower-risk neighbors, and geolocation data is incomplete. SOC teams should monitor for unexpected changes in the subnetβs behavior.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | ORCL-MNT |
| ASN | AS31898 |
| Network Name | SE-ORACLE-SE-20000113 |
| CIDR Block | 213.35.64.0/18 |
| RIR | RIPE |
| Country | GB |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | β |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 27% | 2 | 3 |
| services | 21% | 2 | 2 |
| ownership | 30% | 3 | 4 |
| reputation | 24% | 1 | 3 |
| geolocation | 35% | 2 | 4 |
| Overall | 28% | 12 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-30 17:03:33 UTC |
| Last Seen | 2026-06-21 05:45:29 UTC |
| Profile Built | 2026-06-21 05:49:32 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.