# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 150.136.129.10/32
Classification: Oracle Cloud Infrastructure
Date: 2026-06-17
---
## EXECUTIVE SUMMARY
The IP address 150.136.129.10 is associated with Oracle Public Cloud (ASN 31898) and operates as a low-risk cloud compute instance. Overall risk score is 30/100. The IP hosts a web server (Apache/2.4.52) serving content on rd.udb.edu.sv. Geolocation data shows implausible parameters requiring validation. No active threat indicators or malicious activity observed.
---
## TECHNICAL PROFILE
Infrastructure: Oracle Cloud (apnic RIR)
BGP Prefix: 150.136.0.0/16
Origin ASN: 31898
Network Role: Cloud Compute Instance
Geolocation: Ashburn, VA, US (GeoPlausible: FALSE)
Route Stability: UNSTABLE
Open Services:
- TCP/22 (SSH) - OpenSSH_8.9p1 Ubuntu-3ubuntu0.15
- TCP/80 (HTTP)
- TCP/443 (HTTPS) - Apache/2.4.52
- TCP/8080 (HTTP-alt)
TLS Certificate:
- Issuer: GeoTrust TLS RSA CA G1 / DigiCert Inc
- Subject: CN=rd.udb.edu.sv
- Valid: Self-signed certificate
DNS Configuration:
- PTR Hostnames: Empty
- Forward Resolution: Not confirmed
- Hosted Domains: 0
- Email Auth: SPF/DMARC records absent
- DNSBL Listed: 1 of 8 lists
---
## THREAT INDICATORS
Risk Score: 30/100 (Low Risk)
Abuse Confidence: N/A
Known Attacker: FALSE
Spam Source: FALSE
Tor Exit Node: FALSE
Blacklist Count: 0
Threat Campaigns: None identified
Known Campaigns: 0
---
## GEOLOCATION VALIDATION
Status: IMPLAUSIBLE
- Reported Location: 39.018°N, -77.539°W
- Claimed Distance: 6317.7 km from probe location
- Observed RTT: 23.0ms (minimum possible: 126.4ms)
- Probe Count: 5
- Violation: RTT < minimum possible for claimed distance
---
## NEIGHBORHOOD ANALYSIS
Subnet: 150.136.129.0/24
Abuse Density: 1/10
Classification: Mostly Clean
Inherited Risk: 2/10
Total Siblings: 1
Active Siblings: 1
Threat Siblings: 1
---
## OBSERVATION HISTORY
Total Observations: 22
Recent Activity: 2026-06-17
Threat Persistence: 0 days
Is Persistently Malicious: FALSE
Key Historical Signals:
- HTTP 200 responses with DSpace 8.2 generator detected
- Server banner: Apache/2.4.52 (Ubuntu)
- HTTP/2 support: FALSE
- HSTS: Not enforced
- CSP: Not configured
---
## RELATIONSHIP GRAPH
Total Relationships: 26
Primary Relationship Type: Same Network (OC-195)
Network Affiliation: Multiple peerings to OC-195 network
---
## SECURITY RECOMMENDATIONS
Action Score: 30/100
Recommended Actions: None specified
Firewall Rules: Not generated (risk below threshold)
Suggested Actions:
- Monitor geolocation validation failures
- Review DNSBL listing cause (1 of 8 lists)
- Verify legitimate ownership of rd.udb.edu.sv domain
- Assess necessity of open SSH port on cloud instance
---
END OF BRIEFING
*Intel generated from IPDebrief platform data. Use in conjunction with other threat intelligence sources.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Oracle Public Cloud |
| ASN | AS31898 |
| Network Name | β |
| CIDR Block | β |
| RIR | APNIC |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| 8080 | http-alt | tcp | β |
| Closed Ports | 25, 3389, 8443 (4 open / 7 scanned) | ||
| Server | Apache/2.4.52 (Ubuntu) |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
π TLS Certificate
| SANs | rd.udb.edu.sv |
| Valid From | 2026-03-16T00:00:00+00:00 |
| Valid Until | 2026-09-30T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 198 days |
| Serial Number | 03557B9E7304CE402B8B06DB30079C67 |
| Thumbprint | F6C4C7E976986346E4EB5DDE7C6C6125FAABD6F2 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 26% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 17 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:46 UTC |
| Last Seen | 2026-06-27 00:32:08 UTC |
| Profile Built | 2026-06-27 14:46:20 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.