# IP Intelligence Briefing: 103.167.229.154/32
## Executive Summary
IP address 103.167.229.154 is classified as Low Risk with a risk score of 0. The IP belongs to IRT-MCN-NP (MCN-NP) under ASN 140072 in Nepal. No malicious indicators, threat activity, or blacklist listings were detected. The IP is currently firewalled with no open services.
## Ownership and Geolocation
- Organization: IRT-MCN-NP (MCN-NP)
- ASN: 140072 (Fiberworld Communication Pvt.ltd, NP)
- Country: Nepal (NP)
- CIDR Block: 103.167.228.0/23
- RIR: APNIC
- Registration Date: 2021-06-03
## Network Classification
- Infrastructure Type: Firewalled / No Services
- Open Ports: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0
- DNSBL Listed: 0 of 8 lists checked
## Threat Indicators
No active threat indicators detected. The IP shows:
- No associated threat campaigns
- No known malicious campaigns
- No correlated malicious IPs
- Zero enumeration strikes or WAF violations
- No honeypot hits
## Historical Observations
Twelve observations recorded through 2026-07-25. Key findings:
- Ownership stable with zero changes observed
- DNSSEC validation confirmed (valid)
- No persistent malicious behavior detected
- ASN consistently identified as 140072
- No CDN, VPN, proxy, cloud, or hosting services detected
## Network Neighborhood
Subnet 103.167.229.0/24 classification: Clean
- Abuse Density: 0
- Total Siblings: 2
- Threat Siblings: 0
- Active Siblings: 0
- Risk Distribution: 0 high-risk, 0 medium-risk, 1 low-risk neighbor
- Neighbor IP: 103.167.229.218 (risk score: 25, authority score: 50)
## Relationships
Two network-level relationships identified:
- Same Network: MCN-NP (repeated)
No hostname, organization, or certificate relationships beyond network classification.
## Security Recommendations
Current Risk Score: 0
- No firewall rules or blocking recommendations generated
- No automated actions required
- Standard monitoring recommended for baseline tracking
## Assessment
IP 103.167.229.154 represents legitimate infrastructure with no observable malicious activity. The IP is part of a stable, clean subnet with minimal threat indicators. No immediate action is required beyond standard network monitoring procedures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-MCN-NP |
| ASN | AS140072 |
| Network Name | MCN-NP |
| CIDR Block | 103.167.228.0/23 |
| RIR | APNIC |
| Country | NP |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 3389 | rdp | tcp | — |
| Closed Ports | 22, 25, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | localhost.localdomain |
| Valid From | 2022-08-01T22:39:59+00:00 |
| Valid Until | 2034-01-30T22:39:59+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 4200 days |
🛡️ Public Network Snapshot
| Origin ASN | AS140072 |
| Network Prefix | 103.167.229.0/24 |
| Route mapping | Found |
| HSTS | Enabled |
| CSP | Enabled |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 2 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Mixed Signals (68%) — 2 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
⚠ TLS certificate claims US but primary geo says NP
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-09 01:18:11 UTC |
| Last Seen | 2026-07-25 04:20:26 UTC |
| Profile Built | 2026-07-25 05:07:25 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 103.167.229.154
Who owns the IP address 103.167.229.154?
103.167.229.154 is registered to IRT-MCN-NP. The address falls within the 103.167.228.0/23 network block. Registration is held at APNIC.
Where is 103.167.229.154 located?
Geolocation data places 103.167.229.154 in NP. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 103.167.229.154 malicious or safe?
103.167.229.154 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 103.167.229.154?
Responsive ports observed on 103.167.229.154 include 80, 443, 3389. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.