IP Intelligence Briefing: 161.118.194.153
Date: 2026-06-17
---
**1. Core Profile**
- Risk Rating: Low Risk (Risk Score: 25 / 100)
- Ownership: Owned by Oracle Corporation (ASN: 31898).
- Geolocation: Singapore (SG), Loyang.
- Network Role: Oracle Cloud Compute instance (cloud-hosted, no CDN/VPN/Tor).
- Services: Open RDP port (3389/TCP). No TLS certificates or HTTP services detected.
---
**2. Threat Indicators**
- Malicious Activity: No known malware, phishing, or spam sources.
- Threat Feeds: No indicators in public threat databases.
- DNS/Email: No DNSSEC validation issues, no email authentication records (SPF/DKIM).
---
**3. Observation History**
- Recent Activity (Last 30 Days):
- Minimal risk observed (confidence: 30%).
- One low-confidence observation linked to a Japanese IP (35.6897, 139.6895) with potential threat pulses.
- No persistent malicious behavior or campaign correlations.
---
**4. Network Relationships**
- Subnet Affiliation: Part of Oracle's `ORACLEV6-AP` network (IPv6).
- Connected Entities:
- No direct links to known malicious domains, organizations, or certificates.
- BGP routing shows stable Oracle Cloud infrastructure.
---
**5. Neighborhood Analysis**
- Subnet: `161.118.194.153/24` (no active neighboring IPs reported).
- Abuse Density: Subnet classified as "mostly clean" with no risky siblings.
---
**6. Recommendations**
- Monitor RDP Access: Ensure RDP (port 3389) is secured with multi-factor authentication and restricted to trusted sources.
- Verify Cloud Configuration: Confirm Oracle Cloud instance compliance with security best practices.
- Watch for Subnet Changes: Monitor for unexpected network activity in the `ORACLEV6-AP` subnet.
---
Conclusion: This IP is associated with legitimate Oracle Cloud infrastructure and shows no immediate malicious activity. The open RDP port warrants closer inspection, but overall risk remains low. No actionable threats detected.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | ORACLE CORPORATION - network administrator |
| ASN | AS31898 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:50 UTC |
| Last Seen | 2026-06-27 01:03:20 UTC |
| Profile Built | 2026-06-27 15:15:56 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 27 |
Full dossier details are available via our API.