# Intelligence Briefing: 137.23.50.92/32
## Executive Summary
IP address 137.23.50.92 is a low-risk Oracle Cloud compute instance operating in the Indian region (Mumbai, IN). The IP carries a risk score of 25 and is classified as a single-service host with RDP (port 3389) exposure. No active threat campaigns were identified, and the IP does not appear in major threat intelligence feeds.
## Network Attribution
- Organization: Oracle Corporation (AS31898)
- Network Name: ORACLE-4
- CIDR Block: 137.23.0.0/16
- Infrastructure Type: Cloud Compute (Oracle Cloud)
- Registration RIR: ARIN
## Geolocation and Routing
- Reported Location: Mumbai, India (IN)
- Geolocation Confidence: 1 source, consensus confirmed
- Routing Stability: Route changes detected within 30-day window; isRouteStable: false
- BGP Prefix: 137.23.32.0/19
- Trace Route: 30 hops, final hop latency 207.9ms, 15 timed-out hops via Comcast transit networks
## Threat Indicators
- Risk Score: 25 (Low Risk)
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0
- DNSBL Status: Listed on 1 of 8 DNSBL lists
- Campaign Correlation: None detected; 0 correlated IPs
## Open Services and DNS
- Open Ports: TCP/3389 (RDP)
- PTR Resolution: None
- Forward DNS: No A records resolved
- Hosted Domains: 0
- TLS/Certificates: None detected
## Historical Signals
Observation history captured 20 signals. Recent activity (2026-08-12) showed:
- Country attribution varied between US and IN across different probes
- Operator score rated as "Minimal" (0.1304)
- Single DNSBL listing detected with high severity rating in one observation
- Alienvault OTX signal flagged has_threats: true in one instance
## Neighborhood Analysis
- Subnet: 137.23.50.0/24
- Abuse Density: 1 (mostly clean classification)
- Active Siblings: 1
- Threat Siblings: 1
- No adjacent IPs in the immediate /24 neighbor set
## Relationships
11 relationships identified, all mapping to the ORACLE-4 network. No external hostname, certificate, or organizational relationships beyond the owning network.
## Recommended Actions
No specific firewall rules or remediation actions were generated. The IP presents as a legitimate Oracle Cloud infrastructure endpoint with minimal risk indicators.
## Assessment
This IP represents standard Oracle Cloud infrastructure with no evidence of malicious activity. The RDP exposure on port 3389 warrants attention but does not indicate compromise. The single DNSBL listing appears isolated. Monitoring the IP for changes in service configuration or threat indicators is recommended, particularly given the route instability flag.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Oracle Corporation |
| ASN | AS31898 |
| Network Name | ORACLE-4 |
| CIDR Block | 137.23.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | โ |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 23% | 2 | 2 |
| Overall | 25% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-23 13:56:09 UTC |
| Last Seen | 2026-08-12 17:39:25 UTC |
| Profile Built | 2026-08-12 18:19:55 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.