# Threat Intelligence Briefing: 158.101.18.50/32
Classification: Low Risk | Risk Score: 25/100 | Status: Not Malicious
## Executive Summary
IP address 158.101.18.50 is associated with Oracle Public Cloud infrastructure (ASN 31898, OC-195 network). The IP demonstrates low-risk characteristics with no active threat indicators detected. All neighborhood analysis confirms minimal abuse density within the /24 subnet.
## Technical Profile
- Ownership: Oracle Public Cloud (ASN 31898)
- Network Block: 158.101.0.0/16
- Geolocation: Phoenix, Arizona, US
- Infrastructure Type: Cloud hosting provider
- Services: No open ports detected; service purpose classified as "Firewalled / No Services"
## Threat Assessment
- Abuse Confidence: Not assessed (insufficient evidence)
- Blacklist Status: Listed on 1 of 8 DNSBL feeds
- Threat Indicators: None detected
- Campaign Association: No known campaign correlations
- Campaign Likelihood: Not applicable
## Historical Observation
Twelve signal observations recorded across recent monitoring periods. Key temporal indicators:
- Ownership changes: None
- Threat persistence: Zero days
- Persistently malicious classification: False
- DNSBL listing activity: 1 listing recorded in observation history
## Network Context
- Subnet: 158.101.18.50/24
- Abuse Density: 0.0 (minimal)
- Threat Siblings: 0
- Network Relationships: Multiple relationships mapped to OC-195 Oracle network
## SOC Recommendation
Action: No immediate action required. The IP is associated with legitimate cloud infrastructure with minimal risk indicators. Monitor for any changes in reputation or threat indicators.
Priority: Low
Confidence: Medium (based on limited DNSBL data)
Notes: Oracle Cloud infrastructure IPs frequently appear in DNSBL feeds due to legitimate traffic patterns. No evidence of malicious activity or abuse.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Oracle Public Cloud |
| ASN | AS31898 |
| Network Name | OC-195 |
| CIDR Block | 158.101.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 24% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-08 01:25:41 UTC |
| Last Seen | 2026-08-30 14:57:15 UTC |
| Profile Built | 2026-08-30 15:05:56 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 23 |
Full dossier details are available via our API.