# IP Intelligence Briefing: 158.178.140.2
Classification: Low Risk / Oracle Cloud Infrastructure
Date of Analysis: 2026-08-06
Risk Score: 25/100
## Executive Summary
IP 158.178.140.2 is an Oracle Cloud infrastructure endpoint classified as low risk. The IP is associated with ASN 31898 (ORCL-MNT) and operates within the 158.178.128.0/18 network block. Geolocation data indicates placement in Bungarribee, New South Wales, Australia. No active threat indicators were identified during the investigation.
## Risk Profile
- Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not applicable
- Threat Feed Matches: None
- Blacklist Status: Listed on 1 DNSBL out of 8 total feeds
- Known Campaign Affiliation: None detected
- Campaign Likelihood: None
## Network Classification
- Provider: Oracle Cloud
- Infrastructure Type: Single-Service Host
- Network Role: Oracle network infrastructure
- IP Classification: Clean subnet with no inherited risk
- Subnet Abuse Density: 0/100
## Service Exposure
- Open Ports: TCP 3389 (RDP)
- TLS Certificate: None detected
- HTTP Service: None detected
- DNS Resolution: No PTR hostnames, no forward resolution confirmed
## Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Proxy Service: No
- VPS/Hosting Provider: No
- Mobile/Residential: No
## Historical Observation Summary
17 total observations recorded across 2026-08-06. Recent signals indicate:
- Port scanning activity detected
- Geolocation inference (US coordinates with low confidence)
- Subnet classification as "clean" with zero abuse density
- No ownership changes or persistent malicious activity
- No certificate or banner matches across campaigns
## Neighborhood Analysis
Subnet 158.178.140.2/24 shows:
- Active Siblings: 1
- Threat Siblings: 0
- Abuse Density: Clean
- Risk Distribution: No high-risk neighbors identified
## Relationship Graph
All 5 identified relationships point to "oracle" network entities, confirming the IP's association with Oracle infrastructure. No cross-network relationships or organizational links detected.
## Recommended Actions
No immediate defensive actions required. The IP presents minimal threat to defensive operations. However, the open RDP port (3389) warrants continued monitoring for anomalous access attempts.
## Conclusion
IP 158.178.140.2 is a legitimate Oracle Cloud endpoint with low-risk characteristics. The open RDP service is consistent with cloud infrastructure configurations. No threat indicators or malicious activity patterns were observed. Standard monitoring protocols are sufficient.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | ORCL-MNT |
| ASN | AS31898 |
| Network Name | oracle |
| CIDR Block | 158.178.128.0/18 |
| RIR | ARIN |
| Country | US |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | β |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-01 04:25:09 UTC |
| Last Seen | 2026-08-13 02:21:00 UTC |
| Profile Built | 2026-08-13 02:35:43 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.