IP INTELLIGENCE BRIEFING: 147.15.143.75/32
Executive Summary
The target IP 147.15.143.75 presents a low-risk profile (risk score: 25) associated with Oracle Corporation infrastructure. No active threat indicators or malicious behavior patterns were observed during analysis.
Ownership and Network Classification
The IP is registered under Oracle Corporation (ASN 31898, ORACLE-4) within the 147.15.0.0/16 CIDR block. Geolocation data indicates placement in Quebec, Canada, though geo-validation discrepancies were noted. The infrastructure type is classified as a single-service host with cloud infrastructure attribution to Oracle Cloud.
Security Posture Assessment
- Risk Score: 25 (Low Risk)
- Provider/Authority Scores: 0 (neutral)
- Blacklist Status: Zero blacklist entries
- Abuse Confidence: Not elevated
- Threat Indicators: None detected (no known campaigns, attacker indicators, or spam source attribution)
Service Enumeration
Open ports revealed:
- Port 3389/TCP: RDP service active
No HTTP services, TLS certificates, or other web-facing services were detected. Email authentication (SPF/DMARC) was not configured.
Network Neighborhood Analysis
The /24 subnet (147.15.143.75/24) shows clean classification with zero abuse density. No threat siblings were identified among neighbor IPs. The subnet risk distribution indicates no high or medium-risk neighbors.
Observation History
Fifteen signal observations recorded across the analysis period. Recent observations confirm:
- Subnet classification: Clean
- Abuse density: 0
- No ownership changes detected
- No persistent malicious activity observed
Control Plane Intelligence
- BGP prefix: 147.15.128.0/19
- Route stability: False
- DNSBL listings: 1 of 8 total lists (minimal impact)
- RPKI state and IRR consistency: Data unavailable
Actionable Intelligence
Based on the low-risk profile and Oracle Corporation ownership, this IP is unlikely to require aggressive defensive measures. Standard monitoring practices are appropriate. The RDP service exposure warrants consideration of connection restrictions if the IP is not required for legitimate remote administration access.
Recommendation: Monitor but no immediate blocking required. Verify RDP access necessity against internal network policies.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Oracle Corporation |
| ASN | AS31898 |
| Network Name | ORACLE-4 |
| CIDR Block | 147.15.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | โ |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 2 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 17% | 1 | 1 |
| Overall | 22% | 9 | 11 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-13 03:44:47 UTC |
| Last Seen | 2026-06-21 20:18:31 UTC |
| Profile Built | 2026-06-21 20:23:36 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 17 |
Full dossier details are available via our API.