# IP INTELLIGENCE BRIEFING
Target: 103.114.21.238/32
Classification: Moderate Risk (Score: 40)
Date: Current Intelligence Cycle
---
## EXECUTIVE SUMMARY
IP 103.114.21.238 is a residential/firewalled address in Bogra, Bangladesh (ASN 137579 / BOL System administrator) with a moderate risk score of 40. The IP shows no active threat indicators, no open services, and is currently firewalled. While not immediately malicious, the moderate risk rating warrants monitoring due to elevated DNSBL presence and neighborhood risk context.
---
## NETWORK OWNERSHIP & GEOLOCATION
- Organization: BOL System administrator
- Network Name: BOLSYSTEM-BD
- ASN: 137579 (APNIC RIR)
- Location: Bogra, Rajshahi Division, Bangladesh (24.81°N, 89.31°E)
- CIDR Block: 103.114.21.252/31
- Network Classification: Firewalled / No Services
---
## THREAT ASSESSMENT
Current Risk Profile
| Indicator | Status |
|---|---|
| Risk Score | 40 (Moderate) |
| Blacklist Count | 0 |
| Known Attacker | No |
| Spam Source | No |
| Tor Exit Node | No |
| Active Campaigns | None |
| Persistence Days | 0 |
Control Plane Indicators
- DNSBL Listings: 2 of 8 total lists
- DNSSEC: Valid
- Route Stability: False
- RPKI State: Null
- BGP Prefix: 103.114.21.0/24
---
## NEIGHBORHOOD ANALYSIS
Subnet: 103.114.21.238/24
- Abuse Density: 0
- Classification: Clean
- Total Siblings: 4
- Active Siblings: 1
- Threat Siblings: 0
Neighbor Risk Distribution:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 103.114.21.19 | 25 | 50 |
| 103.114.21.65 | 25 | 50 |
| 103.114.21.111 | 25 | 50 |
---
## OBSERVATION HISTORY
Total Observations: 13 signals (most recent: 2026-07-25)
Key Historical Signals:
- Network Classification: Clean subnet classification with low inherited risk
- Blacklist Activity: IP listed on 2 DNSBLs (max severity: high)
- Service Status: No open ports detected (firewalled)
- Ownership: Stable with no ownership changes
- Threat Persistence: No persistent malicious activity detected
---
## RELATIONSHIP MAPPING
All relationship entities map to the same network infrastructure:
- Primary Entity: BOLSYSTEM-BD (Network)
- Connection Type: Same Network
- Relationship Count: 4
---
## SERVICES & INFRASTRUCTURE
- Open Ports: None (firewalled)
- TLS Certificate: None
- HTTP Title: None
- Forward Resolution: 0 hostnames
- Reverse DNS: None
- Email Authentication: Not configured (no SPF/DMARC)
---
## RECOMMENDED ACTIONS
Immediate
1. Monitor - IP shows moderate risk; no immediate blocking required
2. Block DNSBL - Implement block for 2 active DNSBL listings
3. Log Traffic - Enable logging for inbound/outbound connections
Firewall Rules
```bash
# Allow logging for monitoring
iptables -A INPUT -s 103.114.21.238 -j LOG --log-prefix "MON:"
# Optional: Block if risk threshold increases
iptables -A INPUT -s 103.114.21.238 -j DROP
```
Ongoing
- Monitor neighborhood subnet 103.114.21.0/24 for emerging threats
- Watch for DNSBL listing changes (currently 2 of 8)
- Track route stability changes (currently unstable)
---
## INTELLIGENCE NOTE
This IP represents a legitimate residential/firewalled endpoint in Bangladesh with moderate risk characteristics. The absence of open services and attack indicators suggests defensive posture, though the 2 DNSBL listings indicate prior reputation issues. No immediate threat action required; maintain monitoring posture.
---
Intelligence Product: IPDebrief
Classification: DEFCON 3 / MONITOR
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | BOL System administrator |
| ASN | AS137579 |
| Network Name | BOLSYSTEM-BD |
| CIDR Block | 103.114.21.252/31 |
| RIR | APNIC |
| Country | BD |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS137579 |
| Network Prefix | 103.114.21.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 8% | 2 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-09 19:39:09 UTC |
| Last Seen | 2026-08-26 17:00:20 UTC |
| Profile Built | 2026-08-29 07:50:18 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 18 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 103.114.21.238
Who owns the IP address 103.114.21.238?
103.114.21.238 is registered to BOL System administrator. The address falls within the 103.114.21.252/31 network block. Registration is held at APNIC.
Where is 103.114.21.238 located?
Geolocation data places 103.114.21.238 in Bogra, Rajshahi Division, Bangladesh. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 103.114.21.238 malicious or safe?
103.114.21.238 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.