IP Intelligence Briefing: 161.118.221.49
Date: 2026-06-14
---
**1. Core Profile**
- Risk Score: 25 (Low Risk)
- Ownership: Oracle Corporation (ASN 31898)
- Geolocation: Singapore (SG), Loyang; geo-plausible with 1500km accuracy radius.
- Network Role: Oracle Cloud infrastructure (CloudCompute, Hosting).
- Threat Indicators: No malicious activity detected (no indicators, blacklists, or campaigns).
- Control Plane:
- BGP prefix: `161.118.192.0/18`
- DNSSEC valid, CAA records present, 1 DNSBL listing.
- Route stability: Unstable (route changes in last 30 days).
---
**2. Observation History**
- Latest Activity: June 14, 2026 (CloudCompute infrastructure detection).
- Geolocation Validation: ICMP blocked, but geo-plausible (10,383.8km from probe).
- Temporal Trends: No persistent threats; observed once in last 30 days.
---
**3. Network Relationships**
- Subnet: `161.118.221.49/24`
- Key Relationships:
- Linked to Oracle Cloud network blocks (`ORACLEV6-AP`).
- No direct connections to known malicious entities.
- Subnet Abuse Density: 0.5 (mostly clean, but 1 threat sibling in subnet).
---
**4. Neighborhood Analysis**
- Subnet: `161.118.221.49/24`
- Neighbor Risk:
- `161.118.221.25`: Risk score 25 (low, but higher than the main IP).
- Subnet Classification: "Mostly clean" with inherited risk score 2.
---
**5. Recommendations**
- Monitoring: Track subnet for anomalies, as 1 neighbor shows elevated risk.
- Firewall: No immediate blocking required for this IP, but consider monitoring Oracle Cloud infrastructure traffic.
- Context: Verify if the subnetβs abuse density correlates with broader Oracle Cloud infrastructure activity.
SOC Analyst Note: This IP is part of Oracleβs cloud infrastructure and shows no direct malicious signals. However, the subnetβs mixed risk profile warrants closer scrutiny of neighboring IPs for potential indirect threats.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | ORACLE CORPORATION - network administrator |
| ASN | AS31898 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 17% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-09 17:41:12 UTC |
| Last Seen | 2026-06-27 16:03:14 UTC |
| Profile Built | 2026-06-28 10:09:17 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 28 |
Full dossier details are available via our API.