IPDebrief

140.245.125.139

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP INTELLIGENCE BRIEFING

Target: 140.245.125.139/32

Date: 2026-08-13

Risk Assessment: Moderate Risk (Score: 50/100)

---

OWNERSHIP & NETWORK CLASSIFICATION

The IP address 140.245.125.139 belongs to Oracle Corporation (AS31898, ORACLE-4) within the 140.245.0.0/16 block. The network is classified as Oracle Cloud infrastructure with a clean subnet reputationβ€”abuse density recorded at 0 with no active threat siblings in the /24. The IP serves as a web server with HTTP (80) and HTTPS (443) services open.

GEOLOCATION ANALYSIS

Geolocation data presents inconsistencies. Primary profile data indicates Singapore (Loyang), while historical observations from AlienVault OTX showed US coordinates. This discrepancy warrants monitoring but does not confirm malicious activity. RTT measurements averaged 247.6ms with 5 probe samples.

THREAT INDICATORS

No confirmed threat indicators were identified:

However, the IP appears on 2 of 8 DNSBL lists. Recent history observations flagged the IP as proxy/VPN type with elevated risk scores (66) during specific time windows, indicating transient proxy behavior.

HISTORICAL BEHAVIOR

Analysis of 23 observation signals shows variable risk profiles. Ownership remained stable with no changes recorded. The IP demonstrated no persistent malicious activity and no correlation to known campaigns. Historical data indicates the IP was observed as a VPN/proxy service during certain periods.

RECOMMENDATIONS

Given the moderate risk score and evidence of proxy activity, the following actions are recommended:

1. Block at perimeter: Add to firewall rules (iptables/nftables) and WAF policies

2. Monitor for change: Track if DNSBL listings increase or geolocation stabilizes

3. Allow investigation: If traffic is observed, analyze connection patterns for proxy tunneling

CONCLUSION

140.245.125.139 is a legitimate Oracle Cloud infrastructure IP with moderate risk characteristics primarily driven by transient proxy behavior and DNSBL listings. No active malicious indicators were confirmed. Defensive blocking is recommended pending further observation.

---

*Intel generated by IPDebrief automated analysis system*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΈπŸ‡¬ Singapore
Regionβ€”
CityLoyang
Timezoneβ€”
Latitude1.37
Longitude103.97

🏒 Ownership & Registration

OrganizationOracle Corporation
ASNAS31898
Network NameORACLE-4
CIDR Block140.245.0.0/16
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
Closed Ports22, 25, 3389, 8080, 8443 (2 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
35%
23
routing
13%
11
services
27%
23
ownership
27%
23
reputation
15%
12
geolocation
27%
23
Overall24%1015
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-29 22:49:34 UTC
Last Seen2026-08-13 06:43:50 UTC
Profile Built2026-08-13 00:10:07 UTC
Data FreshnessLive
Signal Types22
Total Observations23
πŸ” 22 signal types Β· 23 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.