IP Intelligence Briefing: 161.118.139.216
Date: 2026-06-10
---
**1. Core Profile**
- Risk Score: 65 (Moderate Risk)
- Ownership: Oracle Corporation (AS31898)
- Geolocation: South Korea (KR), inferred as Seoul.
- Network Role: Oracle Cloud infrastructure (CloudCompute).
- Services: SSH service (OpenSSH 8.2p1) detected.
---
**2. Threat Indicators**
- No direct malicious indicators: No malware, phishing, or exploit activity detected.
- DNSBL Listings: 3/8 DNSBL lists (e.g., Spamhaus, Barracuda) with "high" severity.
- Network Stability: Subnet (161.118.139.0/24) shows 0 abuse density; no neighboring IPs flagged.
---
**3. Historical Observations**
- Recent Activity (2026-06-10):
- DNSBL listings persist (2/8 lists).
- Geolocation inferred as India (20.59°N, 78.96°E) with 1500km accuracy.
- SSH service remains active; no port scanning detected.
- Long-Term Trend: No persistent malicious behavior; risk score stable.
---
**4. Relationships & Network Context**
- Linked Entities:
- Oracle Cloud network (ORACLEV6-AP).
- No connections to known malicious subnets, organizations, or domains.
- Subnet Analysis:
- 161.118.139.0/24 is classified as "clean" with no active threats.
---
**5. Recommendations**
- Monitor DNSBL Listings: Investigate why this IP is listed (e.g., false positives, misconfigurations).
- Validate Geolocation: Confirm if the IPโs inferred location (India) aligns with Oracleโs operations.
- Secure SSH Access: Ensure SSH credentials are protected and restrict access to trusted sources.
- No Immediate Action Required: No evidence of active exploitation or targeting.
---
Conclusion: This IP is associated with Oracle Cloud infrastructure and shows no active malicious behavior. However, its DNSBL listings warrant further investigation to rule out misconfigurations or false positives.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | ORACLE CORPORATION - network administrator |
| ASN | AS31898 |
| Network Name | ORACLEV6-AP |
| CIDR Block | 161.118.0.0/16 |
| RIR | ARIN |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 46% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 27% | 10 | 17 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-25 00:40:31 UTC |
| Last Seen | 2026-06-29 00:51:02 UTC |
| Profile Built | 2026-06-29 06:54:09 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.