# IP Intelligence Briefing: 103.146.202.174
Classification: Low Risk / Cloud Infrastructure
Date: Intelligence generated from current data snapshot
Primary Source: IPDebrief Threat Intelligence Platform
---
## Executive Summary
IP 103.146.202.174 is a low-risk address (Risk Score: 25/100) associated with Indonesian cloud hosting infrastructure. The IP is classified as firewalled with no active services exposed. While the subnet shows mixed risk characteristics, this specific address demonstrates minimal threat indicators and should be treated as standard infrastructure traffic unless anomalous behavior is observed.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **ASN** | 136052 |
| **Organization** | IDNIC-IDCLOUDHOST-ID (PT Cloud Hosting Indonesia) |
| **Country** | Indonesia (ID) |
| **Region** | West Java, Cicurug |
| **CIDR Block** | 103.146.202.0/24 |
| **Reputation** | Low Risk |
| **DNSBL Listed** | 1 of 8 lists |
---
## Network Classification
- Role: Firewalled / No Services Exposed
- Open Ports: None detected
- Infrastructure Type: Cloud Hosting
- Not Classified: Not Tor, CDN, VPN, proxy, or residential
The IP presents no services through port scanning. This is typical for backend infrastructure or misconfigured hosting resources.
---
## Threat Assessment
Current Risk Indicators:
- No active threat indicators identified
- Not flagged as known attacker or spam source
- No Tor exit node activity
- Zero honeypot hits recorded
- No correlation to known malicious campaigns
Observed Threat Persistence: 0 days (non-persistent)
---
## Neighborhood Analysis (103.146.202.0/24)
| Metric | Value |
|---|---|
| **Subnet Abuse Density** | 0 (Low) |
| **Classification** | Mostly Clean |
| **Total Siblings** | 3 |
| **Threat Siblings** | 3 |
Neighbor IP Risk Summary:
- 103.146.202.84: Risk Score 50 (Medium)
- 103.146.202.144: Risk Score 0 (Low)
- 103.146.202.178: Risk Score 25 (Low)
*Note: The subnet exhibits mixed risk characteristics with one medium-risk sibling address. This is common in shared hosting environments.*
---
## Temporal Analysis
Observation History: 22 total signals observed
- Recent Activity: Signals observed as of 2026-06-17
- Ownership Stability: 0 changes recorded
- Route Stability: Stable (confirmed via BGP analysis)
- Threat Persistence: Absent
---
## Control Plane Intelligence
- AS Path: 34549 โ 2914 โ 59796 โ 138608 โ 136052
- BGP Prefix: 103.146.202.0/24
- Route Stability: Stable
- IRR Consistency: Not evaluated
- Operator Score: 0.3913 (Basic)
---
## Recommended Actions
Based on current risk profile, the following actions are appropriate:
1. Allow Traffic: No immediate blocking recommended
2. Monitor: Standard logging and monitoring advised
3. Baseline: Establish traffic baseline for comparison with future anomalies
Firewall Rule Recommendation: No blocking rules required. This IP represents legitimate cloud infrastructure.
---
## SOC Analyst Notes
- Risk Level: LOW
- Primary Concern: None at present
- Action Required: Monitor for behavioral anomalies
- Block Decision: No action required
Context: This IP belongs to Indonesian cloud hosting provider IDNIC. While the subnet contains other higher-risk addresses, this specific IP shows no malicious indicators. Treat as standard infrastructure unless traffic patterns deviate from expected cloud hosting behavior.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-IDCLOUDHOST-ID |
| ASN | AS136052 |
| Network Name | โ |
| CIDR Block | 103.146.202.0/24 |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 30% | 2 | 3 |
| services | 18% | 2 | 2 |
| ownership | 30% | 3 | 4 |
| reputation | 24% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 27% | 12 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:25 UTC |
| Last Seen | 2026-06-22 06:20:53 UTC |
| Profile Built | 2026-06-22 06:27:31 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 25 |
Full dossier details are available via our API.