# IP Intelligence Briefing: 161.118.214.247
Classification: Oracle Cloud Infrastructure Host
Risk Assessment: Moderate Risk (Score: 50)
Date: Current
---
## Executive Summary
IP address 161.118.214.247 is identified as an Oracle Cloud infrastructure host operating within the ORACLEV6-AP network (ASN 31898). The IP exhibits moderate-risk characteristics with a risk score of 50 and is associated with web server services. Geographic data indicates Singapore deployment with some signal inconsistency in historical observations.
---
## Ownership and Network Classification
- Organization: ORACLE CORPORATION - network administrator
- ASN: 31898
- Network Block: 161.118.0.0/16
- Infrastructure Type: Oracle Cloud Provider
- Network Role: Web Server
- Registration: ARIN (161.118.0.0/16)
---
## Technical Profile
Open Services:
- TCP/80 (HTTP)
- TCP/443 (HTTPS)
- TCP/22 (SSH - OpenSSH_9.6p1 Ubuntu-3ubuntu13.18)
Server Stack: OpenResty
DNS Status: Forward resolution not confirmed; 0 hosted domains
TLS/Certificate: No TLS certificate data available
---
## Threat Indicators
- Risk Score: 50 (Moderate)
- Abuse Confidence: Not scored
- Blacklist Status: Listed on 2 of 8 DNSBL lists
- Known Attacker: False
- Tor Exit Node: False
- Known Campaigns: None correlated
- Threat Feeds: No active threat feed matches
---
## Geolocation Analysis
- Primary Location: Singapore (SG)
- Historical Signals: Mixed signals observed (Singapore/India)
- Network RTT: 252-254ms average (1500km accuracy radius)
- Route Stability: Not stable
- BGP Prefix: 161.118.192.0/18
---
## Neighborhood Assessment
- Subnet: 161.118.214.247/24
- Abuse Density: 0 (Clean)
- Sibling IPs: 1 active sibling, 0 threat siblings
- Classification: Clean
---
## Relationship Graph
All 7 identified relationships link to the same network entity: ORACLEV6-AP. No cross-organization or external entity relationships detected.
---
## Historical Observations
19 total observations recorded. Key observations include:
- August 2026: Geolocation signals from India (20.59°N, 78.96°E, 52% confidence)
- August 2026: Operator score 0.15 (Minimal)
- July 2026: Subnet analysis classified as clean (0 abuse density)
- July 2026: Connection failure observed during HTTPS probe
---
## Recommended Security Actions
Firewall Rules (Immediate):
```bash
# iptables
iptables -A INPUT -s 161.118.214.247 -j DROP
# nftables
nft add rule inet filter input ip saddr 161.118.247 drop
# Cloudflare WAF
Block IP 161.118.214.247 (Risk Score: 50)
# AWS WAF
Addresses: 161.118.214.247/32
Description: IPDebrief risk 50
```
Assessment: The moderate risk score (50) combined with DNSBL listings warrants review. However, the clean neighborhood classification and Oracle Cloud infrastructure context suggest this may be legitimate cloud infrastructure with transient risk signals.
---
## Analyst Notes
This IP represents Oracle Cloud infrastructure with moderate risk scoring, likely due to DNSBL listings and non-stable routing. The clean neighborhood density and provider context suggest legitimate hosting operations. SOC teams should evaluate based on specific threat intelligence context and traffic patterns rather than automated blocking alone.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | ORACLE CORPORATION - network administrator |
| ASN | AS31898 |
| Network Name | ORACLEV6-AP |
| CIDR Block | 161.118.0.0/16 |
| RIR | ARIN |
| Country | IN |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | openresty |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 27% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 30% | 2 | 3 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-29 22:49:44 UTC |
| Last Seen | 2026-08-13 06:44:00 UTC |
| Profile Built | 2026-08-13 00:16:33 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 19 |
Full dossier details are available via our API.