# INTELLIGENCE BRIEFING: 103.155.42.38/32
## Executive Summary
IP 103.155.42.38 is a residential address belonging to Chauddagram Broadband (ASN 141038) with an elevated risk profile (70/100). The IP presents geolocation inconsistencies, is listed on 4 DNSBLs, and exhibits residential infrastructure characteristics.
---
## Asset Profile
Network Identity:
- IP Address: 103.155.42.38/32
- Organization: Chauddagram Broadband
- Network Block: 103.155.42.0/24
- ASN: 141038
- RIR: APNIC (Bangladesh region)
- Infrastructure Type: Residential
Geolocation Discrepancy:
- Profile reports: United Kingdom (GB), London
- Historical records indicate: Bangladesh (BD)
- This inconsistency warrants investigation as it may indicate routing anomalies or data corruption
Network Classification:
- Service Purpose: Single-Service Host
- Connection Type: Residential
- Not classified as CDN, VPN, proxy, Tor, or hosting service
---
## Threat Indicators
Risk Assessment:
- Overall Risk Score: 70/100 (High Risk)
- DNSBL Listings: 4 of 8 total lists
- Threat Persistence: 0 days (transient observation)
- Campaign Correlation: No known campaigns
Observed Signals:
- TCP/80 (HTTP) port open
- HTTP response code: 200
- Server response time: 918ms
- No TLS certificates detected
Control Plane Anomalies:
- Route stability: False (not route stable)
- RPKI state: Not reported
- DNSSEC: Valid
---
## Behavioral History
Observation Timeline: 15 observations recorded
Recent Activity: 2026-07-30
- Ownership changes: 0
- Threat persistence duration: 0 days
- Classification: Clean
- Subnet abuse density: 0 (no threat siblings in /24)
Temporal Analysis:
- No persistent malicious behavior detected
- IP shows transient threat characteristics
---
## Network Relationships
Connected Entities:
- Network: CHAUDDAGRAM-BD (2 relationship entries)
- No certificate associations
- No hostnames linked
- No organizational relationships beyond network ownership
Subnet Analysis (103.155.42.0/24):
- Neighbor count: 0 (no discovered siblings)
- Abuse density: 0
- Risk distribution: No high/medium/low risk neighbors identified
---
## Recommended Actions
Immediate Mitigation:
```bash
# iptables
iptables -A INPUT -s 103.155.42.38 -j DROP
# nftables
nft add rule inet filter input ip saddr 103.155.42.38 drop
# NGINX
deny 103.155.42.38;
```
Platform-Specific Rules:
- pfSense: 103.155.42.38/32
- Cloudflare WAF: Block IP with expression `ip.src eq 103.155.42.38`
- AWS WAF: Add address set entry for 103.155.42.38/32
Operational Recommendations:
1. Increase logging verbosity and review recent activity from this IP
2. Monitor for similar residential IPs in the 103.155.42.0/24 block
3. Investigate geolocation inconsistencies with upstream routing data
4. Review DNSBL listing reasons for the 4 blacklist entries
5. Consider blocking the entire /24 subnet if lateral movement is suspected
---
## Intelligence Assessment
This IP presents a moderate-high risk profile primarily driven by its residential nature and DNSBL listings. The geolocation discrepancy between profile (GB) and historical records (BD) is notable and should be correlated with routing data. The residential classification limits attribution but suggests the IP may be used for opportunistic malicious activity.
Confidence Level: Medium
Threat Classification: Suspicious Residential
Recommended Priority: Monitor/Block
---
*Generated from IPDebrief intelligence data. Validate findings against additional threat feeds and correlation data before final disposition.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Chauddagram Broadband |
| ASN | AS141038 |
| Network Name | CHAUDDAGRAM-BD |
| CIDR Block | 103.155.42.0/24 |
| RIR | APNIC |
| Country | BD |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Single-Service Host |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| Closed Ports | 22, 25, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-25 02:40:54 UTC |
| Last Seen | 2026-07-30 01:35:57 UTC |
| Profile Built | 2026-07-30 01:45:02 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.