# IP INTELLIGENCE BRIEFING: 161.118.255.41/32
## Executive Summary
IP address 161.118.255.41 is a cloud-hosted infrastructure endpoint belonging to Oracle Corporation. The IP maintains a low-risk profile with no active threat indicators, though the subnet demonstrates marginal abuse density. RDP service exposure warrants monitoring.
## Infrastructure Profile
- Organization: ORACLE CORPORATION - network administrator
- ASN: 31898 (ORACLEV6-AP)
- CIDR Block: 161.118.0.0/16
- Geolocation: Singapore (SG), Loyang region
- Infrastructure Type: Oracle Cloud Compute (confirmed cloud host)
- Risk Score: 0.0 (Low Risk)
- Provider Score: 0.0
- Authority Score: 0.0
## Network Classification
- Cloud Provider: Yes (Oracle Cloud)
- Hosting Service: Yes
- CDN: No
- VPN/Proxy: No
- Tor Exit Node: No
- Bogon Range: No
- Anycast: No
## Active Services & Exposed Ports
- Port 3389/TCP: RDP (Remote Desktop Protocol) - exposed without additional protection indicators
- No HTTP services detected
- No TLS certificates identified
## Threat Intelligence Indicators
- Abuse Confidence Score: Not assigned
- Blacklist Status: Listed on 8 DNSBLs (max severity: high) per recent observation
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Threat Persistence Days: 0
## Observation History (21 Total Signals)
The IP has been observed since June 2026. Key observations include:
- Cloud infrastructure classification consistently confirmed (Oracle Cloud)
- One observation flagged for listing on 8 threat lists with high severity
- Geographic data shows Singapore consensus (geoPlausible: true)
- No persistent malicious behavior detected (isPersistentlyMalicious: false)
## Network Relationships
- Same Network: 25 relationships identified, all within ORACLEV6-AP network
- No external organizational or hostname relationships detected
- No certificate associations
## Subnet Neighborhood Analysis (161.118.255.0/24)
- Abuse Density: 1 (minimal)
- Classification: Mostly Clean
- Inherited Risk: 2
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
## Control Plane Assessment
- Origin ASN: 31898
- BGP Prefix: 161.118.192.0/18
- Route Stability: Unstable (isRouteStable: false)
- Moas: No
- DNSSEC: Valid
- Operator Score: 0.13 (Minimal)
- DNSBL Listed Count: 8
## Recommended Actions
1. Monitor RDP Exposure: Port 3389 is open; ensure appropriate access controls are in place
2. DNSBL Verification: Investigate listing on 8 DNSBLs to determine cause
3. Subnet Correlation: Monitor sibling IPs in 161.118.255.0/24 for coordinated activity
4. Cloud Provider Notification: Consider notifying Oracle Corporation if abuse is confirmed
## Conclusion
The IP 161.118.255.41 operates as a standard Oracle Cloud endpoint with no active malicious indicators. The primary concern is the exposure of RDP services and the IP's presence on multiple DNSBLs. The subnet shows minimal abuse density with one threat sibling. Recommend continued monitoring but no immediate blocking action unless further evidence emerges.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | ORACLE CORPORATION - network administrator |
| ASN | AS31898 |
| Network Name | ORACLEV6-AP |
| CIDR Block | 161.118.0.0/16 |
| RIR | ARIN |
| Country | IN |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | β |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-09 17:41:12 UTC |
| Last Seen | 2026-06-27 16:04:21 UTC |
| Profile Built | 2026-06-28 16:09:46 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 25 |
Full dossier details are available via our API.