## IP Intelligence Briefing: 103.167.218.34/32
Classification: Moderate Risk (Score: 50/100)
Analysis Date: 2026-07-29
Report Type: Defensive Security Intelligence
---
Executive Summary
IP address 103.167.218.34 is registered to Indonesian infrastructure provider Dedi Seprinra Arfie (AS17995, SOLUSINET-ID). The IP presents a moderate risk profile with no active malicious indicators but exhibits some DNSBL listings. No open services were detected, suggesting firewall protection or non-public-facing infrastructure. The subnet (103.167.218.0/24) shows zero abuse density and clean classification.
---
Infrastructure Profile
| Attribute | Value |
|---|---|
| **IP Address** | 103.167.218.34/32 |
| **Risk Score** | 50 (Moderate) |
| **ASN** | 17995 |
| **Organization** | Dedi Seprinra Arfie |
| **Network** | SOLUSINET-ID |
| **Country** | Indonesia (ID) |
| **Geolocation** | Jakarta, DKI Jakarta |
| **PTR Hostname** | 34.218.167.103.ptr.iforte.net.id |
| **Services** | None detected (Firewalled) |
| **DNS Status** | Inconsistent forward resolution |
---
Threat Indicators
Current Status:
- No known attacker indicators
- Not a Tor exit node
- Not a spam source
- Zero blacklist entries at time of scan
- Operator Risk Score: 0.1304 (Minimal)
DNSBL Presence:
- Listed on 2 of 8 DNSBLs checked
- This may indicate historical activity or false positives
Campaign Correlation:
- No matching threat campaigns
- No correlated IPs in known malware campaigns
---
Neighborhood Analysis
Subnet: 103.167.218.0/24
Abuse Density: 0.0 (Clean)
Risk Classification: Clean
Total Siblings: 1
Active Threat Siblings: 0
The immediate /24 subnet exhibits no malicious activity, with the target IP as the only active sibling.
---
Historical Observation Summary
Total Observations: 18 signals
Recent Activity Period: 2026-07-29
Threat Persistence: None detected
Persistent Malicious Status: False
Recent signals confirm Indonesian geolocation (Jakarta), ASN ownership stability, and consistent registration data. No escalation in threat posture observed.
---
Recommended Actions
Firewall Blocking:
- iptables: `iptables -A INPUT -s 103.167.218.34 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 103.167.218.34 drop`
- nginx: `deny 103.167.218.34;`
WAF/Cloud Protection:
- Cloudflare WAF: Block with expression `ip.src eq 103.167.218.34`
- AWS WAF: Add to protected addresses list
---
Intelligence Assessment
The IP address presents low-to-moderate risk suitable for monitoring without immediate blocking. Key observations:
1. Infrastructure Legitimacy: Registered to established Indonesian ISP with proper RIR registration
2. No Active Threats: Zero known malicious indicators, no open services
3. DNSBL Presence: Minor concernโinvestigate listing sources if traffic impacts occur
4. Clean Neighborhood: Subnet-level analysis shows no correlated abuse
Recommendation: Implement rate limiting or observation rules rather than outright blocking. Monitor for any changes in service exposure or DNSBL status escalation.
---
Disclaimer: This intelligence is based on automated data collection at time of analysis. Validate with additional telemetry before implementing security controls.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dedi Seprinra Arfie |
| ASN | AS17995 |
| Network Name | SOLUSINET-ID |
| CIDR Block | 103.167.218.0/24 |
| RIR | APNIC |
| Country | ID |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 34.218.167.103.ptr.iforte.net.id |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 34.218.167.103.ptr.iforte.net.id |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 13:23:13 UTC |
| Last Seen | 2026-08-13 06:43:20 UTC |
| Profile Built | 2026-08-13 00:40:39 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 21 |
Full dossier details are available via our API.