# INTELLIGENCE BRIEFING: IP 103.125.128.39/32
## EXECUTIVE SUMMARY
IP address 103.125.128.39 is assessed as LOW RISK (Score: 25). The address is associated with KAVINET infrastructure (ASN 58965) and currently shows no active malicious behavior. No immediate defensive action required at this time.
## OWNERSHIP & INFRASTRUCTURE
- Organization: KAVINET (IRT-KAVINET-IN)
- ASN: 58965 (ABSPL-AS-IN - ANJANI BROADBAND SOLUTIONS PVT.LTD.)
- CIDR Block: 103.125.128.0/22
- RIR: APNIC
- Registration: 2018-11-16
## GEOLLOCATION ANALYSIS
- Reported Location: New York, US
- ASN Registry: India (IN)
- Geo Validation: Inconsistent geolocation signals detected (geoConsensus: false, geoPlausible: null). Distance calculations and RTT data unavailable due to firewalled status.
## NETWORK STATE
- Service Status: Firewalled / No Services (no open ports detected)
- DNS: No PTR records, no forward resolution, no hosted domains
- Email Auth: No SPF, DMARC, or TXT records associated
## THREAT PROFILE
- Risk Score: 25 (Low Risk)
- Abuse Confidence: Not applicable (no active threats detected)
- Known Campaigns: None identified
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Status: Listed on 8 DNSBL sources (1 active listing at high severity per history data)
## OBSERVATION HISTORY
Twelve observations recorded. Most recent activity dated 2026-07-27. Key observations:
- DNSSEC validation: Valid
- ASN resolution confirmed (58965, 103.125.128.0/24)
- One blacklist listing detected (high severity)
- No persistent malicious activity observed
- Ownership stable with zero changes
## NEIGHBORHOOD ANALYSIS
- Subnet: 103.125.128.0/24
- Abuse Density: 0 (low)
- Total Siblings: 1
- Threat Siblings: 0
- Neighbor IP: 103.125.128.58 (Risk Score: 25, Authority Score: 50)
The /24 subnet shows minimal abuse activity with only one low-risk neighbor. No high or medium-risk IPs detected in immediate vicinity.
## RELATIONSHIP GRAPH
- Two relationships identified, both classified as "Same Network" targeting KAVINET infrastructure
- No connections to known threat actors, campaigns, or malicious certificates detected
## SECURITY ASSESSMENT & RECOMMENDATIONS
Current Status: LOW RISK
The IP address presents minimal threat to network operations. No active attack indicators or malicious behavior observed.
Defensive Posture
- No immediate blocking required
- Standard monitoring recommended given the single blacklist listing
- No firewall rules generated at this risk level
Monitoring Indicators
- Watch for changes in geolocation consistency (US vs IN discrepancy)
- Monitor for service activation (currently firewalled)
- Track blacklist listing changes
Priority: LOW
This IP should be treated as benign infrastructure. Routine logging and periodic revalidation recommended, but no immediate defensive actions warranted.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-KAVINET-IN |
| ASN | AS58965 |
| Network Name | KAVINET |
| CIDR Block | 103.125.128.0/22 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS58965 |
| Network Prefix | 103.125.128.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 4% | 1 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-14 09:42:25 UTC |
| Last Seen | 2026-09-05 13:08:41 UTC |
| Profile Built | 2026-09-03 21:47:07 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 103.125.128.39
Who owns the IP address 103.125.128.39?
103.125.128.39 is registered to IRT-KAVINET-IN. The address falls within the 103.125.128.0/22 network block. Registration is held at APNIC.
Where is 103.125.128.39 located?
Geolocation data places 103.125.128.39 in Karnāl, Haryana, India. The local time zone is Asia/Kolkata. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 103.125.128.39 malicious or safe?
103.125.128.39 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.