IP INTELLIGENCE BRIEFING
Target: 140.245.125.139/32
Date: 2026-08-13
Risk Assessment: Moderate Risk (Score: 50/100)
---
OWNERSHIP & NETWORK CLASSIFICATION
The IP address 140.245.125.139 belongs to Oracle Corporation (AS31898, ORACLE-4) within the 140.245.0.0/16 block. The network is classified as Oracle Cloud infrastructure with a clean subnet reputationβabuse density recorded at 0 with no active threat siblings in the /24. The IP serves as a web server with HTTP (80) and HTTPS (443) services open.
GEOLOCATION ANALYSIS
Geolocation data presents inconsistencies. Primary profile data indicates Singapore (Loyang), while historical observations from AlienVault OTX showed US coordinates. This discrepancy warrants monitoring but does not confirm malicious activity. RTT measurements averaged 247.6ms with 5 probe samples.
THREAT INDICATORS
No confirmed threat indicators were identified:
- Not a known attacker
- Not a spam source
- Not a Tor exit node
- Zero blacklist hits in threat feeds
However, the IP appears on 2 of 8 DNSBL lists. Recent history observations flagged the IP as proxy/VPN type with elevated risk scores (66) during specific time windows, indicating transient proxy behavior.
HISTORICAL BEHAVIOR
Analysis of 23 observation signals shows variable risk profiles. Ownership remained stable with no changes recorded. The IP demonstrated no persistent malicious activity and no correlation to known campaigns. Historical data indicates the IP was observed as a VPN/proxy service during certain periods.
RECOMMENDATIONS
Given the moderate risk score and evidence of proxy activity, the following actions are recommended:
1. Block at perimeter: Add to firewall rules (iptables/nftables) and WAF policies
2. Monitor for change: Track if DNSBL listings increase or geolocation stabilizes
3. Allow investigation: If traffic is observed, analyze connection patterns for proxy tunneling
CONCLUSION
140.245.125.139 is a legitimate Oracle Cloud infrastructure IP with moderate risk characteristics primarily driven by transient proxy behavior and DNSBL listings. No active malicious indicators were confirmed. Defensive blocking is recommended pending further observation.
---
*Intel generated by IPDebrief automated analysis system*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Oracle Corporation |
| ASN | AS31898 |
| Network Name | ORACLE-4 |
| CIDR Block | 140.245.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 27% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-29 22:49:34 UTC |
| Last Seen | 2026-08-13 06:43:50 UTC |
| Profile Built | 2026-08-13 00:10:07 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.