# IP Intelligence Briefing: 213.35.123.95/32
## Executive Summary
IP 213.35.123.95 is an Oracle Cloud infrastructure endpoint with low-risk characteristics. The IP demonstrates minimal malicious indicators, no known campaign associations, and no persistent malicious behavior. Primary concern is the open RDP port (3389/tcp), which warrants monitoring but does not indicate active compromise.
## Infrastructure Profile
- Risk Score: 25 (Low Risk)
- ASN: 31898 (ORCL-MNT)
- Organization: ORCL-MNT (Oracle Cloud)
- Country: United Kingdom (GB)
- Geolocation: Loyang, GB (500km accuracy radius)
- Network Role: Single-Service Host on Oracle Cloud infrastructure
- BGP Prefix: 213.35.96.0/19
- Route Stability: Unstable
## Threat Assessment
Current Threat Indicators: None observed
- Abuse Confidence: Not applicable
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Status: Listed on 1 of 8 DNSBLs (minor concern)
- Campaign Associations: None
- Threat Persistence: 0 days; not persistently malicious
## Service Exposure
- Open Ports: 3389/tcp (RDP)
- TLS Certificates: None
- HTTP Service: None detected
- DNS Records: No hosted domains, no SPF/DMARC configuration
## Neighborhood Analysis
- Subnet: 213.35.123.95/24
- Abuse Density: 1 (minimal)
- Classification: Mostly clean
- Inherited Risk: 2 (low)
- Threat Siblings: 1
- Active Siblings: 0
## Observation History
18 total observations recorded, most recent on 2026-06-26. Confidence levels ranged from 0.20 to 0.90 across signal types including geolocation, network role classification, port scans, and overall profile assessment. No escalating threat patterns observed.
## Network Relationships
24 relationships identified, all to network entity "SE-ORACLE-SE-20000113" (Same Network classification), confirming integration within Oracle Cloud network infrastructure.
## Recommended Actions
1. Monitor RDP Exposure: Open port 3389/tcp represents potential attack surface. Verify this port is not exposed to the internet or is protected by authentication hardening.
2. DNSBL Review: Investigate the single DNSBL listing to determine context and potential false positive.
3. Baseline Monitoring: Establish traffic baseline for this Oracle Cloud endpoint; current low-risk status supports continued monitoring rather than blocking.
## SOC Analyst Notes
This IP represents legitimate cloud infrastructure with minimal risk posture. The open RDP port is the primary security consideration and should be validated against organizational security policies. No immediate threat response required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | ORCL-MNT |
| ASN | AS31898 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | โ |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 20% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-10 10:13:43 UTC |
| Last Seen | 2026-06-27 17:28:47 UTC |
| Profile Built | 2026-06-28 11:33:39 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 24 |
Full dossier details are available via our API.