IPDebrief

103.109.186.231

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP INTELLIGENCE BRIEFING: 103.109.186.231/32

---

**Executive Summary**

IP address 103.109.186.231 presents a moderate risk profile (risk score: 50) originating from Vietnam. The IP operates as a web server with standard service ports but exhibits no confirmed malicious activity. The subnet classification is clean with zero threat siblings, though DNSBL listings indicate some reputation concerns across 2 of 8 evaluated lists.

---

**Network Ownership & Registration**

FieldValue
**ASN**150826
**Organization**IRT-VNNIC-AP
**Netname**VR-VN
**CIDR Block**103.109.186.0/23
**RIR**APNIC
**Country**Vietnam (VN)
**Abuse Contact**hm-changed@vnnic.vn

---

**Technical Profile**

ComponentDetails
**Server**nginx/1.18.0 (Ubuntu)
**Open Ports**80/tcp (HTTP), 443/tcp (HTTPS), 22/tcp (SSH)
**TLS Certificate**Let's Encrypt (CN=YR1, O=Let's Encrypt, C=US)
**Cert Subject**api.construsolutions.io.vn
**Security Headers**HSTS: enabled, CSP: enabled
**DNSSEC**Valid
**HTTP Status**404

---

**Threat Intelligence Assessment**

---

**Neighborhood Analysis**

Subnet: 103.109.186.0/24

The subnet demonstrates low overall abuse density with no correlated malicious activity in adjacent addresses.

---

**Observation History**

Total observations: 15

---

**Recommended Security Actions**

Risk Score: 50 (Moderate)

While no explicit threat indicators are present, the moderate risk score warrants consideration for blocking:

PlatformRecommended Action
**iptables**`iptables -A INPUT -s 103.109.186.231 -j DROP`
**nftables**`nft add rule inet filter input ip saddr 103.109.186.231 drop`
**nginx**`deny 103.109.186.231;`
**pfSense**`103.109.186.231/32`
**Cloudflare WAF**Block IP (expression: `ip.src eq 103.109.186.231`)
**AWS WAF**Block `103.109.186.231/32`

Note: These recommendations are probabilistic. Combine with additional telemetry and threat intelligence before implementing blocking rules.

---

**Intelligence Narrative**

This IP address represents infrastructure hosted within a Vietnamese network block under IRT-VNNIC-AP. The system runs standard web server software with valid SSL certificates. While the subnet shows clean classification and no active threat siblings, the moderate risk score and presence on multiple DNSBLs suggest potential for abusive activity. The absence of historical threat persistence indicates this IP has not been observed in sustained malicious campaigns. Network defenders should weigh the moderate risk score against operational requirements, considering that the IP may be misconfigured or underutilized rather than actively malicious.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ป๐Ÿ‡ณ Vietnam
Regionโ€”
CityNew York
TimezoneAsia/Ho_Chi_Minh
Latitudeโ€”
Longitudeโ€”

๐Ÿข Ownership & Registration

OrganizationIRT-VNNIC-AP
ASNAS150826
Network NameVR-VN
CIDR Block103.109.186.0/23
RIRAPNIC
CountryVN
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Servernginx/1.18.0 (Ubuntu)
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.10

๐Ÿ” TLS Certificate

๐Ÿ”’
CN=api.construsolutions.io.vn
Issued by CN=YR1, O=Let's Encrypt, C=US
Self-signed: No
SANsapi.construsolutions.io.vn
Valid From2026-07-04T02:50:44+00:00
Valid Until2026-10-02T02:50:43+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period89 days
Serial Number056B15A51C349186DA1A81A28D30EB968D83
Thumbprint062EABE3D494BE396C7558474383187DE85A1053

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
0%
00
Overall12%33
Coverage: 3/6 dimensions ยท Data sufficiency: partial
Data CoherenceMostly Consistent (85%) โ€” 1 contradiction(s)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  High authority score (70) but appears on threat lists (risk 50)

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-25 02:40:54 UTC
Last Seen2026-08-07 13:22:48 UTC
Profile Built2026-08-07 13:23:29 UTC
Data FreshnessLive
Signal Types19
Total Observations19
๐Ÿ” 19 signal types ยท 19 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.