# Intelligence Briefing: 103.165.62.171/32
## Executive Summary
IP address 103.165.62.171 presents a Low Risk profile with no active threat indicators. The address is firewalled with no open services, zero blacklist listings, and no observed malicious activity. However, geolocation data shows conflicting origin indicators requiring further validation.
## Technical Profile
Risk Assessment
- Overall Risk Score: 0 (Low Risk)
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
- Abuse Confidence Score: Not applicable (no abuse data)
Network Classification
- Network Role: Firewalled / No Services
- Open Ports: None detected
- TLS Certificate: Not present
- HTTP Services: None detected
- DNS Records: No PTR hostnames, forward resolution count: 0
- Email Authentication: SPF, DMARC not configured
Geographic Origin
- Primary Indication: United States (NY)
- ASN Origin: 141870 (GVREDDY-AS-IN - GV REDDY BROADBAND SERVICES, IN)
- Note: Geolocation data shows US assignment, but ASN registration indicates Indian origin (IN). This discrepancy requires validation.
Control Plane Data
- Origin ASN: 141870
- BGP Prefix: 103.165.62.0/24
- RPKI State: Not validated
- IRR Consistency: Not validated
- Route Changes (30d): 0
- Route Stability: False
- MOAS Classification: False
## Threat Indicators
Malicious Activity
- Is Tor Exit Node: False
- Is Known Attacker: False
- Is Spam Source: False
- Blacklist Count: 0
- DNSBL Listings: 0 out of 8 lists
- Threat Feeds: None detected
- Campaign Associations: None identified
Behavioral Analysis
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: 0
- Auto-Banned: False
- Active Attacker: False
- Persistently Malicious: False
## Observation History
Signal Timeline (8 observations)
Recent observations from July 29, 2026 show:
- Operator Score: 0.1304 (Minimal)
- DNSSEC Validation: Valid
- ASN Attribution: 141870 - GV REDDY BROADBAND SERVICES
- Threat Persistence: 0 days
- Ownership Changes: 0
Risk Trend
No escalation observed. The IP has maintained a stable, benign profile with no increasing threat signals.
## Network Relationships
Related Entities
- Relationship Graph: No relationships detected
- Associated Hostnames: None
- Linked Organizations: None
- Connected Certificates: None
Subnet Analysis (103.165.62.0/24)
- Total Neighbors: 18
- Abuse Density: 0
- Risk Distribution:
- High Risk: 0
- Medium Risk: 0
- Low Risk: 18
- Notable Neighbors:
- 103.165.62.67 (Risk: 25, Authority: 50)
- 103.165.62.75 (Risk: 25, Authority: 50)
- 103.165.62.170 (Risk: 25, Authority: 50)
- 103.165.62.173 (Risk: 25, Authority: 50)
- 103.165.62.182 (Risk: 25, Authority: 50)
- 103.165.62.184 (Risk: 25, Authority: 50)
- 103.165.62.189 (Risk: 25, Authority: 50)
## Recommended Actions
Immediate
- No action required - IP shows no malicious indicators
- Monitor for any changes in service availability or risk profile
Network Configuration
- Firewall Rules: No specific blocking recommended
- Rate Limiting: Not required
- Geo-blocking: Not recommended (no geographic threat indicators)
Monitoring Parameters
- Port Scan Detection: Monitor for service discovery attempts
- Traffic Anomalies: Monitor for unusual outbound connections
- DNS Queries: Monitor for reverse DNS changes
## Conclusion
IP 103.165.62.171 is classified as Low Risk with no current threat indicators. The subnet (103.165.62.0/24) shows minimal abuse density with 18 low-risk neighbors. The primary action item is to validate the geolocation discrepancy between US assignment and Indian ASN registration. No immediate defensive measures are required.
---
*Report generated: Intelligence Analysis Division*
*Classification: SOC Actionable*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | ROJA GUTTALA |
| ASN | AS141870 |
| Network Name | GVREDDY |
| CIDR Block | 103.165.62.0/23 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 46% | 2 | 3 |
| routing | 22% | 1 | 1 |
| services | 32% | 2 | 2 |
| ownership | 47% | 2 | 3 |
| reputation | 23% | 1 | 2 |
| geolocation | 23% | 1 | 1 |
| Overall | 32% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-23 07:47:51 UTC |
| Last Seen | 2026-07-29 16:45:35 UTC |
| Profile Built | 2026-07-29 22:47:09 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 18 |
Full dossier details are available via our API.