## THREAT INTELLIGENCE BRIEFING
Target: 103.109.100.148/32
Date: 2026-08-01
Classification: Moderate Risk (Score: 59/100)
EXECUTIVE SUMMARY
IP address 103.109.100.148 is a Tor exit node operated by Amarutu Technology Ltd (AMARUTU-AP) in Hong Kong. The address demonstrates moderate risk characteristics with active blacklist listings and Tor exit node indicators.
TECHNICAL PROFILE
| Attribute | Value |
|---|---|
| **ASN** | 206264 |
| **Organization** | Amarutu Technology Ltd administrator |
| **Network** | 103.109.100.0/22 |
| **Geolocation** | Hong Kong, China |
| **Country Code** | HK |
| **RIR** | RIPE NCC |
THREAT INDICATORS
- Tor Exit Node: Confirmed (isTor: true)
- Blacklist Status: Listed on 1 blacklist with high severity
- DNSBL Listings: 0 lists (contradicts blacklist count)
- Abuse Confidence: Moderate risk profile
- Campaign Correlation: No known campaign matches
NETWORK SERVICES
| Port | Protocol | Service |
|---|---|---|
| 22 | TCP | SSH (OpenSSH_10.0p2 Debian) |
| 80 | TCP | HTTP |
| 443 | TCP | HTTPS |
TLS Certificate Analysis:
- Issuer: CN=www.zqz4s5r25s5.com
- Subject: CN=www.xcjpyj7pdu56.net
- Status: Self-signed certificate with suspicious domain naming patterns
OBSERVATION HISTORY
- Total Observations: 45 signals recorded
- Recent Activity: Multiple blacklist listings observed on 2026-08-01
- Listings Count: 8 total, 1 currently listed with high severity
- Risk Trend: Persistent blacklist presence indicates sustained malicious activity
NETWORK CONTEXT
Subnet Analysis (103.109.100.0/24):
- Abuse Density: 1 (elevated)
- Total Siblings: 2
- Active Siblings: 2
- Threat Siblings: 2
- Classification: Mostly clean with inherited risk score of 5
Related IP: 103.109.100.162 (Risk Score: 59, Authority Score: 50)
BGP ROUTING
- Origin ASN: 206264
- BGP Prefix: 103.109.100.0/22
- AS Path: 6939 → 206264
- Route Stability: Stable
RECOMMENDED ACTIONS
Immediate:
1. Block at perimeter: Implement iptables/nftables rule to deny inbound traffic on ports 22, 80, 443
2. Monitor egress: Block outbound connections from internal hosts to 103.109.100.0/24
Firewall Rules:
```
# Block Tor exit node
iptables -A INPUT -s 103.109.100.0/24 -j DROP
nft add rule inet filter input ip saddr 103.109.100.0/24 drop
```
Long-term:
1. Block entire subnet: 103.109.100.0/24 shows elevated abuse density
2. Monitor certificate traffic: Suspicious self-signed certificate patterns
3. Correlate with other Tor nodes: Block associated IPs in same /24 range
INTELLIGENCE NOTES
The target IP represents a known Tor exit node infrastructure. Tor exit nodes are commonly abused for:
- Malware distribution
- Command and control communications
- Spam and phishing campaigns
- C2 server masking
The presence of self-signed TLS certificates with obfuscated domain names (zqz4s5r25s5.com, xcjpyj7pdu56.net) suggests potential C2 infrastructure masquerading as legitimate web services.
Priority: MEDIUM
Action Required: YES - Block at perimeter and monitor egress
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Amarutu Technology Ltd administrator |
| ASN | AS206264 |
| Network Name | AMARUTU-AP |
| CIDR Block | 103.109.100.0/22 |
| RIR | APNIC |
| Country | HK |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | 2026-05-29T00:00:00+00:00 |
| Valid Until | 2027-01-09T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 225 days |
🛡️ Public Network Snapshot
| Origin ASN | AS206264 |
| Network Prefix | 103.109.100.0/22 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 61% | 2 | 33 |
| routing | 27% | 2 | 3 |
| services | 37% | 2 | 3 |
| ownership | 30% | 3 | 4 |
| reputation | 26% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 35% | 12 | 49 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-05 00:55:38 UTC |
| Last Seen | 2026-08-26 18:22:19 UTC |
| Profile Built | 2026-08-29 07:42:47 UTC |
| Data Freshness | Live |
| Signal Types | 27 |
| Total Observations | 29 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 103.109.100.148
Who owns the IP address 103.109.100.148?
103.109.100.148 is registered to Amarutu Technology Ltd administrator. The address falls within the 103.109.100.0/22 network block. Registration is held at APNIC.
Where is 103.109.100.148 located?
Geolocation data places 103.109.100.148 in Hong Kong, HK, Hong Kong. The local time zone is Asia/Hong_Kong. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 103.109.100.148 malicious or safe?
103.109.100.148 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 103.109.100.148?
Responsive ports observed on 103.109.100.148 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.
Is 103.109.100.148 a VPN, proxy, or data center address?
103.109.100.148 is classified as the Tor network based on network ownership and behavioural analysis.