## IP Intelligence Briefing: 103.143.12.43/32
Classification: Moderate Risk
Analysis Date: Current
Target: 103.143.12.43
Executive Summary
IP address 103.143.12.43 presents a moderate risk profile (Risk Score: 50) with conflicting geolocation data and DNSBL listings. The IP is assigned to IRT-HONGKONG5-HK (ASN: 138115) within the IPXO network (103.143.12.0/24) under APNIC. No open services detected; the endpoint is firewalled. Historical data indicates variable geolocation reporting and proxy/VPN classification in recent observations.
Risk Indicators
- Risk Score: 50/100 (Moderate)
- DNSBL Status: Listed on 2 of 8 DNS blacklists (dnsblListedCount: 2)
- Blacklist Count: 0 (contradiction with DNSBL data requires investigation)
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Abuse Confidence Score: Not available
- Operator Score: 0.2609 (Basic)
Network Classification
- Organization: IRT-HONGKONG5-HK
- Network: 103.143.12.0/24 (IPXO)
- ASN: 138115
- RIR: APNIC
- Service Purpose: Firewalled / No Services
- Open Ports: None detected
- TLS Certificates: None
- Cloud/CDN/Proxy/VPN: All false (per primary profile)
Geolocation Discrepancy
Significant conflict exists in geolocation data:
- Primary profile indicates: London, GB (Europe/London timezone)
- Historical signal indicates: Hong Kong, HK
- Geographic consensus: False (geoConsensus: false)
- Two geolocation sources disagree
DNS Analysis
- PTR Record: 103-143-12-43.domainesia.io
- Forward Resolution: Confirmed
- Hosted Domain: domainesia.io
- Email Authentication: No SPF or DMARC records
- DNSSEC: Valid
- CAA Record: None
Behavioral Indicators
- Open Ports: None
- TLS Certificate: None
- HTTP Banner: None
- HSTS/CSP: Not present
- Honeypot Hits: 0
- Threat Persistence Days: 0
Historical Observations (15 signals)
Recent history shows:
- Multiple geolocation signals with conflicting country assignments (GB vs HK)
- One proxy/VPN detection with risk score 66 (source: proxycheck-io)
- RIR assignments consistently APNIC
- Various confidence levels across signal types (0.12–0.95)
Network Relationships
- DNS Association: 103-143-12-43.domainesia.io
- Network Association: IPXO (103.143.12.0/24)
Neighborhood Analysis (103.143.12.0/24)
- Total Siblings: 6
- Abuse Density: 0
- Risk Distribution:
- High Risk: 0
- Medium Risk: 1 (103.143.12.153, Score: 40)
- Low Risk: 5 (remaining neighbors)
- Neighbor Risk Scores: Range from 0–40; no high-risk neighbors identified
Traceroute Analysis
- Hop Count: 17
- First Hop RTT: 0.1ms
- Last Hop RTT: 260.7ms
- Timed Out Hops: 2
- Transit Networks: Comcast, Cogent
Recommended Actions
Based on the moderate risk profile and DNSBL listings, the following defensive measures are recommended:
1. Firewall Rules: Block inbound traffic from 103.143.12.0/24 if the IP is observed initiating connections to internal resources.
2. Monitoring: Implement enhanced logging for any traffic involving this IP, given the geolocation discrepancies and DNSBL presence.
3. DNS Policy: The domainesia.io hostname lacks SPF and DMARC records; verify whether this resolves to legitimate services before allowing email authentication.
4. Neighbor Assessment: No immediate escalation needed based on subnet analysis; only one medium-risk neighbor identified.
Threat Assessment
This IP is not currently flagged as an active attacker, spam source, or Tor exit node. The primary concerns are the DNSBL listings and geolocation inconsistencies. The subnet shows low abuse density with no high-risk neighbors. Continued monitoring is advised pending clarification of geographic origin and DNSBL listing rationale.
---
*Generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-HONGKONG5-HK |
| ASN | AS138115 |
| Network Name | IPXO |
| CIDR Block | 103.143.12.0/24 |
| RIR | APNIC |
| Country | HK |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 103-143-12-43.domainesia.io |
| Forward Confirmed | Yes — FCrDNS verified |
| Forward Hostnames | 103-143-12-43.nevacloud.net103-143-12-43.domainesia.io |
🔐 DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | 0/2 domains |
| DMARC | 0/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS138115 |
| Network Prefix | 103.143.12.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-12 21:05:52 UTC |
| Last Seen | 2026-08-31 23:52:14 UTC |
| Profile Built | 2026-08-31 23:52:49 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 28 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 103.143.12.43
Who owns the IP address 103.143.12.43?
103.143.12.43 is registered to IRT-HONGKONG5-HK. The address falls within the 103.143.12.0/24 network block. Registration is held at APNIC.
Where is 103.143.12.43 located?
Geolocation data places 103.143.12.43 in Jakarta, Jakarta, Hong Kong. The local time zone is Asia/Hong_Kong. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 103.143.12.43 malicious or safe?
103.143.12.43 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 103.143.12.43?
The reverse DNS (PTR) record for 103.143.12.43 is 103-143-12-43.domainesia.io. This hostname is forward-confirmed, meaning it resolves back to the same address.
What ports are open on 103.143.12.43?
Responsive ports observed on 103.143.12.43 include 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.