IPDebrief

103.109.100.148

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

## THREAT INTELLIGENCE BRIEFING

Target: 103.109.100.148/32

Date: 2026-08-01

Classification: Moderate Risk (Score: 59/100)

EXECUTIVE SUMMARY

IP address 103.109.100.148 is a Tor exit node operated by Amarutu Technology Ltd (AMARUTU-AP) in Hong Kong. The address demonstrates moderate risk characteristics with active blacklist listings and Tor exit node indicators.

TECHNICAL PROFILE

AttributeValue
**ASN**206264
**Organization**Amarutu Technology Ltd administrator
**Network**103.109.100.0/22
**Geolocation**Hong Kong, China
**Country Code**HK
**RIR**RIPE NCC

THREAT INDICATORS

NETWORK SERVICES

PortProtocolService
22TCPSSH (OpenSSH_10.0p2 Debian)
80TCPHTTP
443TCPHTTPS

TLS Certificate Analysis:

OBSERVATION HISTORY

NETWORK CONTEXT

Subnet Analysis (103.109.100.0/24):

Related IP: 103.109.100.162 (Risk Score: 59, Authority Score: 50)

BGP ROUTING

RECOMMENDED ACTIONS

Immediate:

1. Block at perimeter: Implement iptables/nftables rule to deny inbound traffic on ports 22, 80, 443

2. Monitor egress: Block outbound connections from internal hosts to 103.109.100.0/24

Firewall Rules:

```

# Block Tor exit node

iptables -A INPUT -s 103.109.100.0/24 -j DROP

nft add rule inet filter input ip saddr 103.109.100.0/24 drop

```

Long-term:

1. Block entire subnet: 103.109.100.0/24 shows elevated abuse density

2. Monitor certificate traffic: Suspicious self-signed certificate patterns

3. Correlate with other Tor nodes: Block associated IPs in same /24 range

INTELLIGENCE NOTES

The target IP represents a known Tor exit node infrastructure. Tor exit nodes are commonly abused for:

The presence of self-signed TLS certificates with obfuscated domain names (zqz4s5r25s5.com, xcjpyj7pdu56.net) suggests potential C2 infrastructure masquerading as legitimate web services.

Priority: MEDIUM

Action Required: YES - Block at perimeter and monitor egress

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇭🇰 Hong Kong
RegionHK
CityHong Kong
TimezoneAsia/Hong_Kong
Latitude22.40
Longitude114.11

🏢 Ownership & Registration

OrganizationAmarutu Technology Ltd administrator
ASNAS206264
Network NameAMARUTU-AP
CIDR Block103.109.100.0/22
RIRAPNIC
CountryHK
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)

🔐 DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierTier 3 — Basic operator with some routing infrastructure
Tor

🔌 Services & Open Ports

PortServiceProtocolBanner
80httptcp—
443httpstcp—
22sshtcpBanner detected
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
CN=www.hobbrgisfqfllttmq.net
Issued by CN=www.suglncd2z6.com
Self-signed: No
SANsNone
Valid From2026-05-29T00:00:00+00:00
Valid Until2027-01-09T23:59:59+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period225 days

🛡️ Public Network Snapshot

Origin ASNAS206264
Network Prefix103.109.100.0/22
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
61%
233
routing
27%
23
services
37%
23
ownership
30%
34
reputation
26%
13
geolocation
32%
23
Overall35%1249
Coverage: 6/6 dimensions · Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) — 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: US, HK

📅 Observation Timeline 🔄 Live

First Seen2026-07-05 00:55:38 UTC
Last Seen2026-08-26 18:22:19 UTC
Profile Built2026-08-29 07:42:47 UTC
Data FreshnessLive
Signal Types27
Total Observations29
🔍 27 signal types · 29 observations collected
This report is generated from 27+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 103.109.100.148

Who owns the IP address 103.109.100.148?

103.109.100.148 is registered to Amarutu Technology Ltd administrator. The address falls within the 103.109.100.0/22 network block. Registration is held at APNIC.

Where is 103.109.100.148 located?

Geolocation data places 103.109.100.148 in Hong Kong, HK, Hong Kong. The local time zone is Asia/Hong_Kong. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 103.109.100.148 malicious or safe?

103.109.100.148 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.

What ports are open on 103.109.100.148?

Responsive ports observed on 103.109.100.148 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.

Is 103.109.100.148 a VPN, proxy, or data center address?

103.109.100.148 is classified as the Tor network based on network ownership and behavioural analysis.

🏘️ Related IP Addresses

Nearby addresses in 103.109.100.0/22

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.