## IP Threat Intelligence Briefing: 103.152.165.117/32
Classification: Moderate Risk (Score: 55/100)
Date Generated: 2026-07-27
Executive Summary
IP 103.152.165.117 is a web server infrastructure endpoint located in Vietnam under ASN 150895 (IRT-VNNIC-AP). The IP maintains a moderate risk profile with no active threat indicators detected. No blacklisting, known attacker activity, or spam source designation observed.
Infrastructure Profile
- Organization: IRT-VNNIC-AP (ZHOST-VN network, 103.152.164.0/23)
- Geolocation: Vietnam (VN) - Asia/Ho_Chi_Minh timezone
- Service Role: Web Server (HTTP/HTTPS on ports 80/443)
- Server Software: LiteSpeed
- TLS Certificate: Self-signed certificate (CN=localhost, generic US locality metadata)
- Network Classification: Provider infrastructure, not CDN/proxy/VPN/Hosting
Threat Indicators Assessment
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0
- Threat Persistence: None observed
- Campaign Correlation: No matches
Neighborhood Analysis
The /24 subnet (103.152.165.0/24) demonstrates clean classification:
- Abuse Density: 0%
- High-Risk Neighbors: 0
- Medium-Risk Neighbors: 0
- Low-Risk Neighbors: 0
- Total Active Siblings: 1
Observation History
17 historical observations recorded. Recent signal analysis confirms:
- Subnet abuse density: 0 (clean)
- No ownership changes detected
- No persistent malicious activity
- TLS 1.3 with TLS_AES_256_GCM_SHA384 cipher suite in use
- DNSSEC validation: Valid
Operational Notes
- Certificate Warning: Self-signed localhost certificate detected; may indicate internal or development server usage
- Geographic Validation: GeoPlausible flag false (potential data source discrepancy, but Vietnam classification consistent with ASN routing)
- Route Stability: Route stability flag indicates minor BGP prefix changes within 30-day window
- DNSBL Listings: 3 of 8 total DNSBL lists (requires context-specific review)
Recommended Actions
- Allow: Standard web traffic (HTTP/HTTPS) appears legitimate for web server function
- Monitor: Self-signed certificate warrants review if not expected for production traffic
- Block: No immediate action required; IP not flagged for threat activity
Conclusion
This IP represents standard web server infrastructure with no active malicious indicators. The moderate risk score primarily reflects the self-signed certificate and geographic location factors rather than confirmed malicious behavior. Recommend standard allow rules with certificate validation monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-VNNIC-AP |
| ASN | AS150895 |
| Network Name | ZHOST-VN |
| CIDR Block | 103.152.164.0/23 |
| RIR | APNIC |
| Country | VN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | 2024-07-08T15:59:29+00:00 |
| Valid Until | 2051-11-23T15:59:29+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 9999 days |
🛡️ Public Network Snapshot
| Origin ASN | AS150895 |
| Network Prefix | 103.152.165.0/24 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Enabled |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Mixed Signals (68%) — 2 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
⚠ TLS certificate claims US but primary geo says VN
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-14 03:39:11 UTC |
| Last Seen | 2026-09-02 17:30:10 UTC |
| Profile Built | 2026-09-02 17:42:35 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 29 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 103.152.165.117
Who owns the IP address 103.152.165.117?
103.152.165.117 is registered to IRT-VNNIC-AP. The address falls within the 103.152.164.0/23 network block. Registration is held at APNIC.
Where is 103.152.165.117 located?
Geolocation data places 103.152.165.117 in Denver. The local time zone is Asia/Ho_Chi_Minh. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 103.152.165.117 malicious or safe?
103.152.165.117 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 103.152.165.117?
Responsive ports observed on 103.152.165.117 include 80, 443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.