## IPDEBRIEF INTELLIGENCE BRIEFING
Target: 103.148.163.215/32
Classification: Moderate Risk (Score: 40)
Report Generated: 2026-07-22
---
EXECUTIVE SUMMARY
IP address 103.148.163.215 is a Pakistan-based infrastructure IP assigned to IRT-OBHOST-PK (ASN 138910) within the AERO-PK network block (103.148.163.0/24). The IP shows moderate risk characteristics with no active threat indicators but is recommended for blocking due to DNSBL listings and moderate risk scoring.
---
OWNERSHIP & GEOLOCATION
- Organization: IRT-OBHOST-PK
- ASN: 138910
- CIDR Block: 103.148.163.0/24
- Country: Pakistan (PK)
- Region/City: Punjab, Faisalabad
- RIR: APNIC
- Registration Status: Active
---
THREAT INDICATORS
| Indicator | Status |
|---|---|
| Known Attacker | No |
| Tor Exit Node | No |
| Spam Source | No |
| Blacklist Count | 0 (threat feeds) |
| DNSBL Listed | 2 of 8 total lists |
| Known Campaigns | None |
| Threat Feeds | None |
Risk Breakdown: Overall risk score of 40 indicates moderate risk. No persistent malicious activity detected.
---
NETWORK PROFILE
- Service Purpose: Firewalled / No Services
- Open Ports: None
- TLS Certificate: None
- HTTP Services: None
- Network Role: Infrastructure (firewalled)
DNS Analysis:
- PTR Hostnames: None
- Forward Resolution: Inactive
- Hosted Domains: 0
- Email Authentication: No SPF, no DMARC records
---
NEIGHBORHOOD ASSESSMENT
- Subnet: 103.148.163.0/24
- Abuse Density: 0 (Clean)
- Threat Siblings: 0
- Active Siblings: 0
- Subnet Classification: Clean
The /24 subnet shows no abuse activity, indicating this IP operates in isolation without associated malicious peers.
---
RELATIONSHIP GRAPH
- Network Association: AERO-PK (2 relationships)
- Related Entities: No external connections (subnets, hostnames, organizations, certificates)
---
OBSERVATION HISTORY
Total Observations: 11 (Recent: 2026-07-22)
- Ownership Changes: 0
- Threat Persistence Days: 0
- Is Persistently Malicious: No
- Route Stability: Unstable (route changes detected)
- DNSSEC Valid: Yes
Recent signals indicate consistent ownership and classification with no emerging threat patterns.
---
RECOMMENDED ACTIONS
Based on risk profile and DNSBL listings, the following blocking rules are recommended:
Firewall/Network:
```
iptables -A INPUT -s 103.148.163.215 -j DROP
nft add rule inet filter input ip saddr 103.148.163.215 drop
```
Web Application:
```
nginx: deny 103.148.163.215;
```
Cloud WAF:
```
Cloudflare WAF: Block (risk score 40)
AWS WAF: Block 103.148.163.215/32
```
---
ANALYST NOTES
This IP presents moderate risk with DNSBL listings but lacks active threat indicators. The subnet remains clean. Blocking is recommended due to reputation scoring and DNSBL presence, though false positives should be considered given the lack of active threat signals. Monitor for changes in route stability or emergence of threat indicators.
---
Data Sources: IPDebrief Intelligence Platform
Confidence Level: Medium (based on DNSBL listings and risk scoring)
Classification: Operational Intelligence
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-OBHOST-PK |
| ASN | AS138910 |
| Network Name | AERO-PK |
| CIDR Block | 103.148.163.0/24 |
| RIR | APNIC |
| Country | PK |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS138910 |
| Network Prefix | 103.148.163.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-02 04:20:20 UTC |
| Last Seen | 2026-08-24 13:13:35 UTC |
| Profile Built | 2026-08-29 09:47:50 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 16 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 103.148.163.215
Who owns the IP address 103.148.163.215?
103.148.163.215 is registered to IRT-OBHOST-PK. The address falls within the 103.148.163.0/24 network block. Registration is held at APNIC.
Where is 103.148.163.215 located?
Geolocation data places 103.148.163.215 in Faisalabad, Punjab, Pakistan. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 103.148.163.215 malicious or safe?
103.148.163.215 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.