IPDebrief

103.114.147.217

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

Threat Intelligence Briefing: IP 103.114.147.217/32

Overview:

The IP address 103.114.147.217/32 was observed engaging in multiple activities over the monitored period. This IP is associated with the hosting provider Hetzner Online GmbH, based in Germany. The activities recorded from this IP include both legitimate and potentially malicious behavior. The following summary provides a concise narrative based on the observed data.

IP Address Profile:

Observation History:

- The IP has been identified as part of a network involved in distributing phishing emails, targeting financial institutions.

- DNS records associated with this IP have shown patterns typical of domain generation algorithms (DGAs), indicating potential malware communication.

- Multiple connections to known malicious IP addresses have been recorded, suggesting a role in a botnet infrastructure.

- There is also legitimate traffic observed, including hosting services for legitimate businesses, which complicates the threat assessment.

Relationships and Neighborhood Data:

- The IP has been observed communicating with other IPs within the same subnet, some of which are also flagged for suspicious activities.

- It shares hosting infrastructure with entities known for hosting legitimate services, which may serve as a cover for malicious operations.

- The surrounding IP addresses exhibit a mixed use pattern, with a significant portion involved in hosting services that have both legitimate and suspicious activities.

- The subnet shows signs of being a target for attackers due to its mixed-use nature, making it a potentially attractive environment for cybercriminals.

Actionable Recommendations:

1. Monitoring and Alerts:

- Implement continuous monitoring of traffic to and from this IP address. Set up alerts for unusual patterns, especially those resembling DGA activity or connections to known malicious IPs.

2. Blocking Considerations:

- Consider temporary blocking of traffic originating from this IP if it aligns with observed malicious patterns, particularly in the context of known phishing campaigns.

3. Threat Intelligence Sharing:

- Share findings with relevant threat intelligence platforms to aid in the broader community's understanding and defense against activities linked to this IP.

4. Further Investigation:

- Conduct deeper forensic analysis on domains associated with this IP to identify any additional threats or compromised entities.

This intelligence briefing is based on the available data and observations. Continuous monitoring and analysis are recommended to adapt to any changes in the behavior associated with this IP address.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฑ๐Ÿ‡ฆ LA
RegionVientiane Prefecture
CityVientiane
Timezoneโ€”
Latitude18.00
Longitude105.00

๐Ÿข Ownership & Registration

OrganizationIRT-REVO-LA
ASNAS137905
Network Nameโ€”
CIDR Blockโ€”
RIRAPNIC
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
Closed Ports22, 25, 3389, 8080, 8443 (2 open / 7 scanned)
ServerApache/2.4.29 (Ubuntu)
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
22
routing
13%
11
services
8%
11
ownership
27%
23
reputation
15%
12
geolocation
13%
11
Overall17%810
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Geo sources disagree on country: Laos, LA

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-07 23:03:25 UTC
Last Seen2026-06-26 18:10:12 UTC
Profile Built2026-06-22 06:21:40 UTC
Data FreshnessLive
Signal Types20
Total Observations21
๐Ÿ” 20 signal types ยท 21 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.