# IP Intelligence Briefing: 168.138.195.242
Classification: Moderate Risk
Risk Score: 50/100
Date: 2026-07-30
---
## Executive Summary
IP 168.138.195.242 is a firewalled address within Oracle Cloud infrastructure (ASN 31898, BGP prefix 168.138.192.0/20). No active services or open ports detected. The IP appears on 2 of 8 blacklist feeds but shows no active threat indicators or known campaign associations.
---
## Technical Profile
- Infrastructure: Oracle Cloud (provider score 0, authority score 0)
- Network Classification: Cloud infrastructure, firewalled/no services
- DNSSEC: Valid (zone: 242.195.138.168.in-addr.arpa)
- Route Stability: Unstable (route changes: 0, isRouteStable: false)
- Open Ports: None detected
- TLS/HTTP: No certificates, banners, or web services
---
## Threat Indicators
- Blacklist Status: Listed on 2 of 8 DNSBL feeds (max severity: high)
- Known Attacker: False
- Tor/Proxy/VPN: Negative
- Abuse Confidence Score: Not calculated
- Historical Threat Persistence: 0 days (not persistently malicious)
---
## Behavioral Analysis
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: 0
- Active Attacker Status: Inactive
---
## Neighborhood Analysis
- Subnet: 168.138.195.0/24
- Abuse Density: 0 (no sibling IPs identified)
- Risk Distribution: No high-risk neighbors detected
- Active Siblings: 0
---
## Observation History
Seven observations recorded, most recent from 2026-07-30. Signals indicate:
- Oracle Cloud provider identification (confidence: 0.90)
- DNSSEC validation (confidence: 0.90)
- Blacklist presence (confidence: 0.85, 2/8 listings)
- Operator score: 0.1304 (minimal operator activity)
---
## Recommended Actions
No immediate blocking recommended. The IP shows cloud infrastructure characteristics with no active threat indicators. However, maintain monitoring due to:
1. Blacklist presence on 2 feeds
2. Unstable route configuration
3. Moderate risk classification
Actionable Firewall Rules:
- Allow traffic if legitimate cloud service required
- No explicit drop rules needed at this time
- Monitor for service activation on this IP
---
## Intelligence Notes
This IP lacks active threat signatures despite moderate risk classification. The blacklist presence may indicate historical abuse or false positives. Oracle Cloud infrastructure hosting suggests legitimate cloud service usage. No relationships to other malicious IPs detected. SOC analysts should maintain baseline monitoring without escalation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Oracle Public Cloud |
| ASN | AS31898 |
| Network Name | OC-195 |
| CIDR Block | 168.138.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.13 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 22:49:47 UTC |
| Last Seen | 2026-08-13 06:44:03 UTC |
| Profile Built | 2026-08-13 00:16:33 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 22 |
Full dossier details are available via our API.