# IP Intelligence Briefing: 146.235.16.130/32
Classification: Moderate Risk | Risk Score: 65/100 | Severity: High (Monitoring)
---
## 1. Ownership & Network Classification
The IP 146.235.16.130 belongs to Oracle Corporation (ASN 31898) under the ORACLE-4 network block (146.235.0.0/18). The infrastructure is classified as Oracle Cloud provider infrastructure with a firewalled/no services designation.
Key Attributes:
- Organization: Oracle Corporation
- ASN: 31898 (ORACLE-4)
- CIDR Block: 146.235.0.0/18
- Geolocation: Singapore (SG), Loyang
- Geographic Consensus: True (multiple sources agree)
- Geographic Plausibility: False (notable discrepancy between Singapore registry and probe data)
---
## 2. Threat Assessment
Current Threat Posture: No direct malicious indicators detected.
Threat Indicators:
- Blacklist Count: 0
- Known Attacker: No
- Spammer Source: No
- Tor Exit Node: No
- Known Campaigns: None
- DNSBL Listed: 3 of 8 lists
Control Plane Analysis:
- BGP Prefix: 146.235.16.0/21
- Route Stability: False
- RPKI Validation: Not configured
- DNSSEC: Valid
- Operator Score: 0.1304 (Minimal)
---
## 3. Service & Network Activity
Services: No open ports detected; HTTP/TLS services unavailable.
DNS Analysis:
- PTR Hostnames: None
- Forward Resolution: Not confirmed
- Hosted Domains: 0
- Email Authentication: No SPF, DMARC, or TXT records configured
---
## 4. Observation History
Observation Count: 12 signals recorded
Temporal Trends:
- Recent activity shows geographic data discrepancies (some sources reporting US locations vs. Singapore registry)
- No ownership changes detected
- No persistent malicious behavior observed
- Threat observation count: 0
- Threat persistence days: 0
Recent Signals (Last 24 Hours):
- Ownership signals: Stable (0 changes)
- Geolocation: Mixed sources (US and SG)
- Operator classification: Minimal risk
- DNSSEC validation: Present
---
## 5. Neighborhood Analysis
Subnet: 146.235.16.0/24
Risk Distribution:
- High Risk: 0
- Medium Risk: 0
- Low Risk: 1
Abuse Density: 0%
Sibling IP:
- 146.235.16.244: Risk Score 25/100 (Low risk)
Threat Correlation: No correlated threat siblings detected.
---
## 6. Relationship Graph
All 4 relationship links point to the same network entity (ORACLE-4). No external relationships detected to:
- Hostnames or domains
- Organizations (beyond Oracle)
- SSL certificates
- External subnets
---
## 7. Recommended Security Actions
Priority: High (Monitoring Required)
Recommended Actions:
1. Increase logging verbosity for traffic from this IP
2. Review recent activity patterns and timing
3. Monitor for service enumeration attempts
Firewall Rule Implementation:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 146.235.16.130 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 146.235.16.130 drop` |
| nginx | `deny 146.235.16.130;` |
| pfSense | `146.235.16.130/32` |
| Cloudflare WAF | Block IP (risk score 65) |
| AWS WAF | Block 146.235.16.130/32 |
---
## 8. Analyst Assessment
This IP represents Oracle Cloud infrastructure with a moderate risk profile. The elevated risk score (65/100) without direct threat indicators suggests potential for opportunistic abuse rather than organized malicious activity. Geographic discrepancies between registry data (Singapore) and probe data (various US locations) warrant monitoring for routing anomalies or potential spoofing.
Immediate Action: Monitor inbound/outbound traffic patterns. Implement blocking rules if activity patterns indicate abuse. The neighbor IP (146.235.16.244) presents low risk and may serve as a baseline for comparison.
Classification: Provider infrastructure with moderate monitoring requirements. No immediate takedown recommended unless suspicious activity patterns emerge.
---
*Report generated using IPDebrief intelligence platform. All data based on observed signals as of the latest collection cycle.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Oracle Corporation |
| ASN | AS31898 |
| Network Name | ORACLE-4 |
| CIDR Block | 146.235.0.0/18 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| 8443 | https-alt | tcp | β |
| Closed Ports | 25, 80, 443, 3389, 8080 (2 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
π TLS Certificate
| SANs | *.6121999.dpdns.org6121999.dpdns.org |
| Valid From | 2026-08-03T00:32:16+00:00 |
| Valid Until | 2026-11-01T00:32:15+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 050ED5E677232139B1913DC9663A8855EDEC |
| Thumbprint | DEBF00A39577BDBE5DA23E75BE05EC49DADEC213 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 13% | 1 | 1 |
| Overall | 20% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-29 22:49:37 UTC |
| Last Seen | 2026-08-13 00:06:37 UTC |
| Profile Built | 2026-08-13 00:16:33 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.