# IP INTELLIGENCE BRIEFING: 217.142.184.43/32
Classification: Low Risk | Risk Score: 30 | Date: 2026-06-20
---
## EXECUTIVE SUMMARY
IP address 217.142.184.43 is associated with Oracle Cloud infrastructure (ASN: 31898) and presents low risk characteristics. However, the /24 subnet (217.142.184.0/24) shows elevated abuse density with one threat-identified sibling IP. The IP exhibits mixed geographic attribution signals and maintains standard web server services. No immediate blocking is required, but monitoring is recommended due to neighborhood context.
---
## NETWORK IDENTIFICATION
| Attribute | Value |
|---|---|
| **IP Address** | 217.142.184.43 |
| **ASN** | 31898 (ORCL-MNT) |
| **Organization** | Oracle Cloud |
| **Geolocation** | GB/Singapore (discrepant signals) |
| **Classification** | Oracle Cloud Web Server |
| **Network Stability** | Route not stable (route changes observed) |
---
## SERVICE FINGERPRINT
Open Ports:
- TCP/80 (HTTP)
- TCP/443 (HTTPS)
- TCP/22 (SSH - OpenSSH 9.6p1 Ubuntu)
- TCP/8080 (HTTP-Alt)
Server Banner: openresty
TLS Certificate: Not detected
Email Authentication: SPF/DMARC not configured
---
## THREAT ANALYSIS
Current Threat Indicators:
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- CDN/Proxy/VPN: No
- Blacklist Count: 0 (threat section) / 1 (DNSBL listed)
Abuse Signals:
- DNSBL Listed: 1 of 8 total lists
- Abuse Confidence Score: Not reported
- Known Campaigns: None identified
---
## OBSERVATION HISTORY (Last 20 Signals)
Recent Activity:
- 2026-06-20 02:45: Oracle Cloud provider confirmed (90% confidence)
- 2026-06-20 02:45: Geo-location GB with 750km accuracy radius
- 2026-06-20 02:45: Proxycheck-io signal: Singapore (Jurong East) with risk score 66, classified as proxy/VPN
- 2026-06-15: Connection failure observed on HTTPS
- 2026-06-15: Port scanning activity recorded
Temporal Analysis:
- Threat Observation Count: 1
- Is Persistently Malicious: No
- Ownership Changes: 0
---
## NEIGHBORHOOD CONTEXT
Subnet: 217.142.184.0/24
- Abuse Density: 1 (elevated)
- Subnet Classification: mostly_clean
- Threat Siblings: 1
- Active Siblings: 0
- Total Siblings: 1
Assessment: The immediate /24 subnet shows elevated abuse density, with one threat-identified neighbor. This IP shares the subnet but does not inherit malicious classification.
---
## CONTROL PLANE DATA
| Metric | Value |
|---|---|
| BGP Prefix | 217.142.184.0/21 |
| Route Stability | Not stable |
| Route Changes (30d) | 0 |
| DNSSEC Valid | Yes |
| Operator Score | 0.1304 (Minimal) |
---
## RECOMMENDATIONS
Immediate Actions: None required (risk score 30, low risk)
Monitoring Priorities:
1. Monitor for changes in threat indicators
2. Track geographic signal consistency
3. Watch subnet abuse density trends
Firewall Rules: No specific rules generated. Standard allow policies may be applied with logging enabled.
---
## ANALYST NOTES
The IP demonstrates Oracle Cloud infrastructure characteristics with mixed geographic attribution signals (GB vs Singapore). The subnet context warrants attention due to one threat sibling, though this specific IP maintains low-risk classification. Historical data shows sporadic connection failures and port scanning activity. Continued monitoring recommended pending any risk score elevation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | ORCL-MNT |
| ASN | AS31898 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| 8080 | http-alt | tcp | โ |
| Closed Ports | 25, 3389, 8443 (4 open / 7 scanned) | ||
| Server | openresty |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 25% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-17 09:10:40 UTC |
| Last Seen | 2026-06-28 04:52:05 UTC |
| Profile Built | 2026-06-28 22:57:55 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.