# IP Intelligence Briefing: 161.118.212.147
Classification: Moderate Risk | Date: July 2026
---
## Executive Summary
IP address 161.118.212.147 presents a moderate risk profile (score: 50/100) with observed infrastructure hosted on Oracle Cloud. The address is located in Singapore but has inconsistent geolocation data. The IP is actively listed on 2 of 8 threat intelligence feeds with high-severity listings and operates SSH and RDP services, indicating potential for lateral movement or unauthorized access vectors.
---
## Technical Profile
Infrastructure:
- Provider: Oracle Cloud
- ASN: 31898
- BGP Prefix: 161.118.192.0/18
- Network Role: Multi-Service Host
- Geolocation: Singapore (SG) β Consensus confirmed with 1 source
Service Footprint:
- Port 22 (TCP): SSH β OpenSSH 9.6p1 Ubuntu-3ubuntu13.18
- Port 3389 (TCP): RDP β Banner unavailable
- DNS Resolution: Forward confirmation failed
- Email Authentication: No SPF or DMARC records detected
Threat Indicators:
- DNSBL Listings: 2 of 8 total lists (high-severity)
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
---
## Temporal Analysis
Observation History (12 total signals):
- Recent Activity: July 29, 2026
- Geolocation Discrepancy: One low-confidence (0.35) observation from India (IN), conflicting with primary Singapore location
- Blacklist Activity: Confirmed presence on 8 threat feeds with 2 high-severity listings
- Network Scanning: Multiple port scans detected (ports 22, 3389, and others)
- DNSSEC: Valid (RRSIG absent)
- Route Stability: Not stable β indicates recent routing changes
---
## Neighborhood Assessment
Subnet Analysis (161.118.212.0/24):
- Abuse Density: 0%
- Active Siblings: 0
- High/Medium Risk IPs: 0
- Neighboring Threats: None detected
The absence of sibling threat activity suggests this IP may operate in isolation within its /24 allocation.
---
## Relationship Graph
No external relationships detected (0 relationships). The IP shows no associations with known organizations, hostnames, certificates, or correlated IP addresses.
---
## Recommended Actions
Immediate:
1. Block inbound RDP (3389): Service exposed without additional authentication controls
2. Monitor SSH (22): Verify legitimate administrative access; consider rate limiting
3. Verify DNSBL Listings: Investigate the 2 high-severity blacklist entries for source and context
Firewall Rules:
```
# Block RDP from this IP (if not authorized)
iptables -A INPUT -p tcp -d 161.118.212.147 --dport 3389 -j DROP
# Rate limit SSH
iptables -A INPUT -p tcp -d 161.118.212.147 --dport 22 -m limit --limit 3/min -j ACCEPT
iptables -A INPUT -p tcp -d 161.118.212.147 --dport 22 -j DROP
```
Long-term:
- Correlate the India geolocation observation with network traffic patterns
- Monitor for changes in route stability and BGP announcements
- Investigate DNSBL listing sources for potential reputation contamination
---
Analyst Notes: The combination of Oracle Cloud infrastructure, RDP exposure, and blacklist presence warrants monitoring. No immediate malicious activity confirmed, but the moderate risk score and service exposure suggest defensive hardening is prudent.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | ORACLE CORPORATION - network administrator |
| ASN | AS31898 |
| Network Name | ORACLEV6-AP |
| CIDR Block | 161.118.0.0/16 |
| RIR | ARIN |
| Country | IN |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| 3389 | rdp | tcp | β |
| Closed Ports | 25, 80, 443, 8080, 8443 (2 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 45% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 39% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-23 20:05:10 UTC |
| Last Seen | 2026-08-13 06:46:11 UTC |
| Profile Built | 2026-08-13 12:16:14 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 48 |
Full dossier details are available via our API.