IPDebrief

103.167.234.20

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 103.167.234.20/32

Date: 2026-07-29

Classification: Low Risk

Analyst: IPDebrief Intelligence Team

---

## Executive Summary

IP address 103.167.234.20 is associated with AlbHost SH.P.K. (ASN 48014) under the AHS-AP network block (103.167.234.0/23). The address maintains a risk score of 25 (Low Risk) with no active threat indicators. The subnet demonstrates minimal abuse density (0.0), and the IP has been observed without malicious activity. No firewall action is currently recommended based on available intelligence.

---

## Network Attribution

AttributeValue
**Organization**AlbHost SH.P.K.
**ASN**48014
**Network Block**103.167.234.0/23
**RIR**APNIC
**Abuse Contact**abuse@albahost.net
**Registration**APNIC registry

---

## Geolocation Analysis

ParameterValue
**Country**Poland (PL)
**Region**Mazovia
**City**Warsaw
**Coordinates**52.18°N, 21.06°E
**Timezone**Europe/Warsaw
**Geo Validation**Mixed signals; claimed location: Albania in historical data

*Note: Geolocation consistency issues detected. Primary consensus indicates Poland; historical observations suggest Albania. Investigate potential misattribution or infrastructure changes.*

---

## Threat Intelligence Assessment

Current Threat Status: None Detected

IndicatorStatus
**Risk Score**25 / 100
**Abuse Confidence**N/A
**Known Attacker**No
**Spam Source**No
**Tor Exit Node**No
**Blacklist Count**0
**DNSBL Listings**1 of 8 (minor)
**Known Campaigns**None
**Threat Persistence**0 days

---

## Network Services & DNS

Service Exposure: None Detected

DNS Analysis:

---

## Relationship Graph

Network Associations:

DNS Associations:

No external organizational or certificate relationships identified.

---

## Neighborhood Analysis (103.167.234.0/24)

MetricValue
**Total Siblings**1
**Active Siblings**0
**Threat Siblings**0
**Abuse Density**0.0
**Subnet Classification**Clean

The subnet demonstrates clean operational characteristics with no adjacent threat activity.

---

## Control Plane Analysis

ParameterValue
**Origin ASN**48014
**BGP Prefix**103.167.234.0/24
**Route Stability**False
**Route Changes (30d)**0
**RPKI State**Not Available
**DNSSEC Valid**True
**IRR Consistency**Not Available
**Operator Score**0.1304 (Minimal)

---

## Historical Observations

Total observations: 17

Key Historical Signals:

---

## Recommended Actions

Current Recommendation: No Action Required

The IP address presents no immediate threat. However, the following monitoring parameters are advised:

1. Monitor DNS resolution consistency โ€“ Forward confirmation failed; verify service legitimacy

2. Track geolocation anomalies โ€“ Investigate Poland/Albania location discrepancies

3. Watch subnet activity โ€“ Monitor for emergence of threat indicators in 103.167.234.0/24

Firewall Rules: Not applicable at this time based on risk profile.

---

## Intelligence Conclusion

IP 103.167.234.20 is a low-risk address operated by AlbHost SH.P.K. with no active threat indicators. The subnet remains clean with no adjacent malicious activity. Geolocation inconsistencies warrant periodic review but do not indicate active compromise. No firewall blocking is recommended; continue standard monitoring practices.

Confidence Level: High

Last Updated: 2026-07-29 13:11:25 UTC

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ต๐Ÿ‡ฑ Poland
RegionMazovia
CityWarsaw
TimezoneEurope/Warsaw
Latitude52.18
Longitude21.06

๐Ÿข Ownership & Registration

OrganizationAlbHost SH.P.K.
ASNAS48014
Network NameAHS-AP
CIDR Block103.167.234.0/23
RIRAPNIC
CountryAL
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRip-103-167-234-20.static.albahost.net
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesip-103-167-234-20.static.albahost.net

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCPresent
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Servernginx/1.22.1
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u10

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
25%
11
Overall16%44
Coverage: 4/6 dimensions ยท Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-22 13:23:13 UTC
Last Seen2026-07-29 13:05:41 UTC
Profile Built2026-07-29 13:18:50 UTC
Data FreshnessLive
Signal Types20
Total Observations20
๐Ÿ” 20 signal types ยท 20 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.