# IP Intelligence Briefing: 140.245.201.77/32
Classification: Cloud Infrastructure / Moderate Risk (Score: 50)
## Executive Summary
IP 140.245.201.77 is an Oracle Cloud infrastructure address located in New York, US. The IP exhibits a moderate risk profile (score 50) primarily driven by DNSBL listings rather than active malicious behavior. No open services are detected, and the subnet shows minimal abuse density. Recommended action is monitoring with optional blocking pending additional context.
## Infrastructure Profile
- Owner/Provider: Oracle Corporation (ASN 31898)
- Geolocation: New York, US (US-NY)
- CIDR Block: 140.245.192.0/18
- Registration Date: 2022-09-07
- Network Role: Cloud Infrastructure / Firewalled
- Infrastructure Type: Unknown
## Threat Assessment
Risk Score: 50/100 (Moderate)
Threat Indicators:
- DNSBL Listed: 2 of 8 total lists
- Max Severity: High (from blacklist feeds)
- No known attacker indicators
- Not a Tor exit node
- No spam source activity detected
- No active campaigns correlated
Service Exposure: No open ports detected. IP is described as "Firewalled / No Services" with zero open ports, no TLS certificates, and no HTTP services.
## Observational History
Nine signal observations recorded as of 2026-07-29. Recent signals confirm:
- DNSSEC validation: Valid
- ASN resolution: ORACLE-BMC-31898 (Oracle Corporation, US)
- PTR record: Absent
- Blacklist activity: 2 listings with high severity
No ownership changes or persistent threat patterns observed.
## Network Relationships
- Related Entities: None identified
- Subnet Analysis: 140.245.201.0/24 shows zero active siblings and zero abuse density
- Control Plane: Route stability flagged as false; 30-hop traceroute via Comcast with 13 timed-out hops
## Recommended Security Actions
The risk profile warrants defensive consideration:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 140.245.201.77 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 140.245.201.77 drop` |
| pfSense | Block 140.245.201.77/32 |
| Cloudflare WAF | Block with expression: `ip.src eq 140.245.201.77` |
| AWS WAF | Block 140.245.201.77/32 |
Note: These recommendations are probabilistic. Given the IP is Oracle Cloud infrastructure with no active service exposure, blocking should be evaluated against business requirements and verified against internal threat intelligence before deployment.
## Analyst Notes
This IP represents typical Oracle Cloud infrastructure behavior. The moderate risk score is primarily blacklist-driven rather than behavior-based. The absence of open services and neighbors suggests this is likely a passive or internal cloud address. Monitor for changes in service exposure or increased blacklist activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Oracle Corporation |
| ASN | AS31898 |
| Network Name | ORACLE-4 |
| CIDR Block | 140.245.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | โ |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 37% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 25% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 19:32:17 UTC |
| Last Seen | 2026-08-12 17:05:33 UTC |
| Profile Built | 2026-08-12 17:18:39 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.