Intelligence Briefing for IP 103.150.191.59/32
Overview:
The IP address 103.150.191.59/32 was analyzed for its network behavior, ownership, and potential threat profile. The data gathered from various sources provides a comprehensive view of its activities and associations.
Ownership and Attribution:
- Owner: The IP address 103.150.191.59/32 is registered to a known hosting provider, which is commonly used by various legitimate services.
- ASN: The IP is associated with the Autonomous System Number (ASN) that corresponds to the hosting provider, indicating its use for hosting services.
Observation History:
- Traffic Patterns: Historical data indicates typical web traffic patterns consistent with a hosting service. There were no unusual spikes or anomalies in traffic volume that would suggest malicious activity.
- Geolocation: The IP is geolocated in a region known for hosting data centers and cloud services, aligning with its use by a hosting provider.
Threat Intelligence:
- Malicious Activity: There is no direct association with known malicious domains or IP ranges in threat intelligence databases. The IP does not appear on any high-risk blacklists.
- Relationships: The IP address does not show direct connections to known command and control (C2) servers or phishing campaigns. Its interactions are primarily with other IPs associated with the hosting provider.
Neighborhood Data:
- Subnet Analysis: The subnet 103.150.191.0/24 shows a pattern of IPs used for web services, with no significant anomalies or associations with malicious entities.
- Peer IPs: Surrounding IPs in the subnet are similarly used for hosting and do not exhibit any signs of compromise or malicious behavior.
Conclusion:
Based on the analysis, IP 103.150.191.59/32 appears to be a legitimate hosting IP with no current indicators of compromise or malicious intent. It is associated with a reputable hosting provider and exhibits normal traffic patterns typical for hosting services. While always advisable to monitor for changes, the current data does not warrant any immediate threat response from SOC teams.
Recommendations:
- Continue Monitoring: Regularly monitor traffic patterns for any deviations from established norms.
- Update Threat Feeds: Ensure threat intelligence feeds are current to detect any future associations with malicious activity.
- Incident Response Plan: Maintain readiness to investigate any future anomalies or alerts associated with this IP.
This briefing provides a factual summary based on available data, intended to support SOC analysts in their defensive operations.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | NOC BiznetGIO |
| ASN | AS133800 |
| Network Name | IDNIC-BIZNETGIO-ID |
| CIDR Block | 103.150.191.0/24 |
| RIR | APNIC |
| Country | ID |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ip-59-191-150-103.wjv-1.biznetg.io |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | ip-59-191-150-103.wjv-1.biznetg.io |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 27% | 2 | 3 |
| services | 28% | 2 | 4 |
| ownership | 24% | 2 | 3 |
| reputation | 21% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 24% | 11 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:25 UTC |
| Last Seen | 2026-06-22 06:22:23 UTC |
| Profile Built | 2026-06-22 06:27:31 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 27 |
Full dossier details are available via our API.