## IP Intelligence Briefing: 140.245.33.202/32
Classification: Oracle Cloud Infrastructure - Moderate Risk
Date: 2026-08-08
Executive Summary
IP address 140.245.33.202 was identified as a moderate-risk Oracle Cloud infrastructure endpoint. The IP belongs to Oracle Corporation (ASN 31898, ORACLE-4) and is geolocated to Singapore. No active threat indicators were detected, but the IP carries a risk score of 50/100 and appears on 2 of 8 DNSBL lists.
Infrastructure Profile
- Organization: Oracle Corporation (ORACLE-4)
- CIDR Block: 140.245.0.0/16
- Network Role: Oracle Cloud, CloudCompute infrastructure
- Geolocation: Singapore, SG
- Network Type: Cloud infrastructure (is_cloud: true, is_hosting: true)
Threat Assessment
The IP exhibits moderate risk characteristics:
- Risk Score: 50/100 (Moderate Risk)
- DNSBL Status: Listed on 2 of 8 threat lists
- Known Threat Indicators: None detected
- Campaign Associations: No known campaigns linked
- Tor/Proxy/VPN: Not detected
Network Context
The surrounding /24 subnet (140.245.33.0/24) shows clean neighborhood characteristics:
- Abuse Density: 0
- Neighbor Count: 2 detected neighbors (140.245.33.62, 140.245.33.146)
- Neighbor Risk Scores: 25/100 each (Low Risk)
- Threat Siblings: 0
Observation History
17 historical observations were recorded. Recent signals confirm Oracle Cloud infrastructure classification. A routing anomaly was observed on 2026-07-30 showing New York, US connectivity via Comcast, indicating potential multi-region routing or geographic inconsistencies. No persistent malicious activity or threat persistence was detected over the observation period.
Relationships
All 8 detected relationships point to the ORACLE-4 network block. No associated hostnames, external organizations, or certificate subjects were identified.
Recommended Actions
While no specific blocking recommendations were generated due to the moderate risk classification, standard defensive posture suggests:
- Monitor: Track outbound and inbound traffic patterns from this IP
- Block: Consider blocking if internal policies require blocking all Oracle Cloud IPs or if specific threat indicators emerge
- Firewall Rules: Generic drop rules available for iptables, nftables, nginx, pfSense, Cloudflare WAF, and AWS WAF
Conclusion
IP 140.245.33.202 represents Oracle Cloud infrastructure with moderate risk characteristics. The IP is not definitively malicious but carries reputation risk indicators. SOC teams should monitor traffic from this IP without immediate blocking, unless internal threat detection systems flag additional suspicious behavior. The clean neighborhood context and lack of active threat indicators support a cautious monitoring approach.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Oracle Corporation |
| ASN | AS31898 |
| Network Name | ORACLE-4 |
| CIDR Block | 140.245.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 23% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-29 22:49:34 UTC |
| Last Seen | 2026-08-13 12:52:32 UTC |
| Profile Built | 2026-08-13 00:10:08 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.