IP INTELLIGENCE BRIEFING: 140.238.16.177/32
Classification: Moderate Risk | Risk Score: 50/100
Infrastructure: Oracle Public Cloud (ASN 31898) | Network: OC-195 (140.238.0.0/16)
---
SUMMARY
IP 140.238.16.177 is an Oracle Cloud infrastructure endpoint registered in Seoul, South Korea. The address exhibits moderate risk characteristics primarily driven by DNSBL listings, but lacks confirmed malicious activity indicators. No active threat campaigns or known attacker associations detected.
---
OWNERSHIP & GEOLOCATION
- Organization: Oracle Public Cloud
- ASN: 31898 (OC-195)
- Registered Country: KR (Seoul, South Korea)
- Network Classification: CloudCompute, Hosting infrastructure
- RTT Validation: 227ms average to Seoul (8,465km distance), geolocation plausible
---
THREAT INDICATORS
- DNSBL Status: Listed on 1 of 8 total blacklists
- Abuse Confidence: Not assessed
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Threat Feeds: No matches detected
- Campaign Correlation: None identified
---
NETWORK NEIGHBORHOOD ANALYSIS
- /24 Subnet (140.238.16.0/24): Clean classification
- Abuse Density: 0 (no detected abuse)
- Threat Siblings: 0
- High/Medium Risk Neighbors: 0
---
HISTORICAL SIGNALS (23 Observations)
Recent monitoring shows:
- Provider consistently identified as Oracle Cloud
- Geolocation signals validated for Seoul, KR
- One low-confidence US geolocation signal (0.35 confidence) observed
- No evidence of persistent malicious behavior
- Risk profile stable over observation period
---
RECOMMENDATIONS
1. Monitor DNSBL listings โ Address appears on one blacklist; review specific listing reason
2. No immediate blocking required โ Infrastructure is legitimate Oracle Cloud; blocking may impact valid services
3. Standard cloud traffic monitoring recommended for /16 range
4. Investigate if traffic patterns indicate abuse โ No current evidence of misuse
---
EVIDENCE SOURCES
- IPDebrief Risk Profile
- DNSBL listing records
- RTT-based geolocation validation
- Historical signal observations (23 data points)
---
*Report generated from IPDebrief intelligence platform data. All information derived from automated threat intelligence sources.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Oracle Public Cloud |
| ASN | AS31898 |
| Network Name | OC-195 |
| CIDR Block | 140.238.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 22% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 22:49:34 UTC |
| Last Seen | 2026-08-13 06:43:50 UTC |
| Profile Built | 2026-08-13 00:16:34 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.