# IP INTELLIGENCE BRIEFING
Target IP: 103.117.163.40/32
Date of Analysis: 2026-07-29
Classification: Low Risk / Network Infrastructure
---
## 1. PROFILE SUMMARY
Risk Assessment: Low Risk (Score: 25/100)
Ownership: ASN 150371 | IRT-EBONE1-PK | EBONE1-PK
Geolocation: United Kingdom (GB) - London
Network Role: Firewall / No Services Detected
The IP belongs to an infrastructure network with minimal operator activity (Operator Score: 0.1304). The subnet 103.117.163.0/24 shows route stability issues but maintains valid DNSSEC validation.
---
## 2. THREAT INDICATORS
Abuse Confidence: None detected
Blacklist Status: 0/8 lists
Threat Classifications:
- Not a Tor exit node
- Not a known attacker IP
- Not a spam source
- No known campaigns associated
- No threat feed matches
Network Services: No open ports detected (service purpose: "Firewalled / No Services")
DNS Resolution: No PTR records, forward resolution not confirmed, zero hosted domains
---
## 3. OBSERVATION HISTORY
Total Observations: 15 signals
Observation Period: 2026-07-29 (most recent)
Threat Persistence: 0 days
Ownership Changes: 0
Recent observations show:
- Geolocation signals (confidence: 50-85%)
- Network scanning activity (ports scanned: 5+ ports)
- Operator classification: "Minimal" threat level
- No persistent malicious behavior detected
Temporal Analysis: No threat persistence observed. The IP has not been flagged as persistently malicious across the observation window.
---
## 4. RELATIONSHIP ANALYSIS
Linked Entities: 3 relationships identified
Primary Association: EBONE1-PK network (Same Network)
The IP is consistently associated with the EBONE1-PK network designation. No organizational or certificate relationships detected. No subnets or hostnames beyond the network-level association.
---
## 5. SUBNET NEIGHBORHOOD
Subnet: 103.117.163.0/24
Total Neighbors: 6
Abuse Density: 0%
Neighbor Risk Distribution:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 103.117.163.38 | N/A | N/A |
| 103.117.163.42 | 25 | 50 |
| 103.117.163.45 | N/A | N/A |
| 103.117.163.54 | 25 | 50 |
| 103.117.163.75 | 25 | 50 |
| 103.117.163.197 | N/A | N/A |
Assessment: Subnet contains 3 low-risk and 3 medium-risk IPs. Abuse density is minimal. The target IP matches the risk profile of its neighbors (Risk: 25, Authority: 50).
---
## 6. CONTROL PLANE & INFRASTRUCTURE
BGP Prefix: 103.117.163.0/24
Origin ASN: 150371
Route Stability: False (route changes detected in 30 days: 0)
DNSSEC: Valid
IRR Consistency: Not applicable
Route Changes (30d): 0
MOAS Status: No
Anycast: No
---
## 7. TRACEROUTE & NETWORK PATH
Hop Count: 30
Transit Networks: Comcast, Cogent
Timed Out Hops: 9
Minimum Possible RTT: 108.6ms
ICMP Status: Blocked (unable to validate)
---
## 8. SECURITY ACTIONS & RECOMMENDATIONS
Risk Score: 25/100
Recommended Actions: None required
Firewall Rules: Not applicable
Given the low-risk classification and lack of malicious indicators, no immediate blocking or filtering actions are recommended. The IP presents as standard network infrastructure with no active threat signals.
---
## 9. ANALYST NOTES
This IP address represents a low-risk network infrastructure endpoint. The firewall designation and lack of open services suggest legitimate network equipment rather than a compromised host. The subnet exhibits minimal abuse density and the IP's risk profile aligns with neighboring addresses. No correlation with known threat campaigns or malicious infrastructure.
Monitoring Recommendation: Continue passive observation. No immediate action required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-EBONE1-PK |
| ASN | AS150371 |
| Network Name | EBONE1-PK |
| CIDR Block | 103.117.163.0/24 |
| RIR | APNIC |
| Country | PK |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-21 12:54:20 UTC |
| Last Seen | 2026-07-29 08:05:38 UTC |
| Profile Built | 2026-07-29 08:15:58 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.