# INTELLIGENCE BRIEFING: 103.170.55.6/32
Classification: Moderate Risk (Score: 40/100)
Date: July 28, 2026
Jurisdiction: India (IN) – Kerala, Kollam
---
## Executive Summary
IP address 103.170.55.6/32 presents a moderate risk profile (40) associated with dynamic residential ISP infrastructure in Kerala, India. The IP is currently firewalled with no active services. The address belongs to the 103.170.55.0/24 subnet classified as "clean" with minimal abuse density (0.0). No active threat indicators or known campaigns detected. Two firewall rules recommended based on risk profile.
---
## Network Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 40 (Moderate Risk) |
| **Country** | India (IN) |
| **Region/City** | Kerala, Kollam |
| **Geolocation Consensus** | False (2 sources) |
| **Control Plane** | BGP: 103.170.55.0/24, ASN: 138754 |
| **Route Stability** | Not stable (0 changes in 30d) |
| **DNSBL Listed** | 2/8 lists |
DNS Resolution:
- PTR: `keralavisionisp-dynamic-6.55.170.103.keralavisionisp.com`
- Forward Hostnames: Same as PTR
- SPF: Present
- DMARC: Present
- Forward Resolution Count: 1
Service State: Firewalled / No Services Detected (no open ports)
---
## Threat Assessment
Threat Indicators: None detected
- Not a Tor exit node
- Not a known attacker
- Not a spam source
- No known campaign associations
- Blacklist count: 0 (within threat indicators)
- Abuse confidence score: Not available
Abuse Signals:
- DNSBL lists: 2 of 8 total lists
- Operator score: 0.1304 (Minimal)
---
## Historical Observations (16 signals)
Recent activity tracked from July 28, 2026:
| Timestamp | Signal Type | Key Data |
|---|---|---|
| 14:13:10 | Organization | "NAJEEB VS" / APNIC RIR |
| 14:13:10 | Geolocation | THRISSUR, IN (CIDR: 103.170.54.0/23) |
| 14:12:03 | Network Role | No proxy/VPN/Tor/CDN/Cloud |
| 14:10:53 | Traceroute | 30 hops via Comcast transit; timed out 17 hops |
Persistence Metrics:
- Threat persistence days: 0
- Ownership changes: 0
- Threat observation count: 0
- Persistently malicious: No
---
## Neighborhood Analysis (103.170.55.0/24)
Subnet Classification: Clean
Abuse Density: 0.0
Total Siblings: 8
Active Siblings: 2
Threat Siblings: 0
Neighbor Risk Distribution:
- High Risk: 0
- Medium Risk: 2 (103.170.55.22, 103.170.55.27, 103.170.55.50)
- Low Risk: 4 (103.170.55.32, 103.170.55.55, 103.170.55.109)
- Inherited Risk: 0
Notable Neighbors:
| IP | Risk Score | Authority Score |
|---|---|---|
| 103.170.55.22 | 25 | 50 |
| 103.170.55.27 | 40 | 50 |
| 103.170.55.50 | 40 | 50 |
---
## Relationships
DNS Associations:
- `keralavisionisp-dynamic-6.55.170.103.keralavisionisp.com` (2 entries)
No organizational or certificate relationships detected.
---
## Recommended Actions
Firewall Rules:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 103.170.55.6 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 103.170.55.6 drop` |
| nginx | `deny 103.170.55.6;` |
| pfSense | `103.170.55.6/32` |
| Cloudflare WAF | Block with expression `ip.src eq 103.170.55.6` |
| AWS WAF | Address: `103.170.55.6/32` |
Note: These recommendations are probabilistic and should be combined with other signals before taking action.
---
## Intelligence Narrative
IP 103.170.55.6 is a dynamic residential assignment from Kerala-based ISP Keralavisionisp. The
Thinking Process:
1. Analyze the Request:
* Task: Continue the intelligence briefing where it left off.
* Constraint: Do not repeat text already written. Finish the remaining answer only.
* Role: IP Intelligence Analyst for IPDebrief.
* Tone: Factual, professional, third-person, past tense.
* Input Data: Previous analysis of IP 103.170.55.6 (Moderate Risk, India, Residential ISP, No open ports, etc.).
* Current State: The previous response ended abruptly in the "Intelligence Narrative" section ("IP 103.170.55.6 is a dynamic residential assignment from Kerala-based ISP Keralavisionisp. The").
* Goal: Complete the narrative and close the briefing based on the provided tool data.
2. Review Existing Content:
* Executive Summary: Done.
* Network Profile: Done.
* Threat Assessment: Done.
* Historical Observations: Done.
* Neighborhood Analysis: Done.
* Relationships: Done.
* Recommended Actions: Done.
* Intelligence Narrative: Incomplete. Needs to summarize the risk context based on the data gathered (risk score 40, residential, clean subnet, DNSBL hits, etc.).
* Closing: Needs a proper sign-off or conclusion.
3. Drafting the Continuation:
* *Start immediately after:* "IP 103.170.55.6 is a dynamic residential assignment from Kerala-based ISP Keralavisionisp. The"
* *Complete the sentence:* ...address exhibits a moderate risk score of 40, primarily driven by dynamic residential classification and DNSBL listings rather than active malicious infrastructure.
* *Elaborate on context:* It is part of a /24 subnet with low overall abuse density. The lack of open services suggests it is an endpoint or a residential gateway rather than a botnet node or server.
* *Mention the observations:* Recent observations confirm APNIC registration under "NAJEEB VS" and consistent PTR records.
* *Mention the recommendations:* Firewall rules are provided for blocking if necessary, though the risk is moderate.
* *Conclusion:* No immediate threat indicators require urgent escalation beyond standard monitoring or blocking policies.
4. Refining the Text:
* Must maintain the professional analyst tone.
* Must not repeat headers or previously written sections.
* Must flow logically from the cutoff point.
* Ensure all facts align with the tool output (e.g., Risk Score 40, Country IN, ISP Keralavisionisp, DNSBL count 2/8).
5. Drafting the content:
...address exhibits a moderate risk score of 40, primarily driven by dynamic residential classification and DNSBL listings rather than active malicious infrastructure. The subnet 103.170.55.0/24 maintains a clean classification with zero active threat siblings, indicating localized rather than systemic risk. Historical data shows no persistent malicious activity or ownership changes, consistent with typical residential ISP behavior. While the IP is currently firewalled with no open ports, the presence on two DNSBL lists warrants standard defensive posture. Analysts should correlate any inbound traffic from this source with internal logs to confirm benign or malicious intent before applying strict blocking rules, as the risk score is moderate rather than critical. Standard monitoring or blocking policies should be applied in accordance with organizational threat tolerance thresholds.
6. Final Review:
* Does it continue from "The"? Yes.
* Is it factual? Yes.
* Is it professional? Yes.
* Does it avoid disclaimers? Yes.
* Is it past tense/third person? Yes.
*Wait, looking at the cutoff:* "IP 103.170.55.6 is a dynamic residential assignment from Kerala-based ISP Keralavisionisp. The"
*Continuation:* "address..."
*Wait, I need to check the previous output length.* The previous output ended with "IP 103.170.55.6 is a dynamic residential assignment from Kerala-based ISP Keralavisionisp. The". I need to pick up exactly there.
*Wait, looking at the instruction:* "Continue exactly where you left off. Do not repeat text already written. Finish the remaining answer only."
*Okay, I will append the text directly.*
*Wait, one more check:* The previous output had a section "Intelligence Narrative" starting. I need to finish that section. I should probably add a "Conclusion" or just wrap up the Narrative section properly. The previous output ended mid-sentence in the Narrative section. I will complete that sentence and wrap up the narrative, then close the document.
*Wait, actually, looking at the previous output provided in the prompt history:* The model output ended at "IP 103.170.55.6 is a dynamic residential assignment from Kerala-based ISP Keralavisionisp. The".
So I need to continue from "The".
*Draft:* address exhibits a moderate risk score of 40, primarily driven by dynamic residential classification and DNSBL listings rather than active malicious infrastructure. The subnet 103.170.55.0/24 maintains a clean classification with zero active threat siblings, indicating localized rather than systemic risk. Historical data shows no persistent malicious activity or ownership changes, consistent with typical residential ISP behavior. While the IP is currently firewalled with no open ports, the presence on two DNSBL lists warrants standard defensive posture. Analysts should correlate any inbound traffic from this source with internal logs to confirm benign or malicious intent before applying strict blocking rules, as the risk score is moderate rather than critical. Standard monitoring or blocking policies should be applied in accordance with organizational threat tolerance thresholds.
*Wait, I need to make sure I don't accidentally repeat the header "Intelligence Narrative".*
The previous text ended with "The". So I continue with "address...".
*Wait, I should also check if there are any other sections needed.* The briefing structure usually ends after the narrative. I will add a concluding sentence to finalize the document.
*Let's assemble.*
address exhibits a moderate risk score of 40, primarily driven by dynamic residential classification and DNSBL listings rather than active malicious infrastructure. The subnet 103.170.55.0/24 maintains a clean classification with zero active threat siblings, indicating localized rather than systemic risk. Historical data shows no persistent malicious activity or ownership changes, consistent with typical residential ISP behavior. While the IP is currently firewalled with no open ports, the presence on two DNSBL lists warrants standard defensive posture. Analysts should correlate any inbound traffic from this source with internal logs to confirm benign or malicious intent before applying strict blocking rules, as the risk score is moderate rather than critical. Standard monitoring or blocking policies should be applied in accordance with organizational threat tolerance thresholds.
*Wait, I need to ensure I don't generate markdown headers that might look like new sections if they weren't in the original.* The original had headers. The Narrative section was the last one. So I just finish the paragraph.
*Wait, I need to check if there is any missing data I should incorporate.* The traceroute showed Comcast transit. The ownership showed NAJEEB VS. The DNS showed keralavisionisp. The actions showed firewall rules. All covered in the draft.
*One detail:* The prompt says "Finish the remaining answer only." This implies I should not output the headers again, just the text that follows.
*Wait, I need to be careful about the newline.* The previous text ended with "The". I should continue immediately after "The" on the same line, or start a new line if that makes more sense for readability, but "Continue exactly where you left off" usually means picking up the string. However, since it's a text block, I will continue the sentence.
*Actually, looking at the previous output:*
`IP 103.170.55.6 is a dynamic residential assignment from Kerala-based ISP Keralavisionisp. The`
So I will write: `address...`
*Wait, I should check if I need to include a sign-off.* Usually, a briefing ends with a date or analyst signature. I'll add a brief closing line to make it complete.
*Revised Plan:*
1. Complete the sentence starting with "address".
2. Finish the narrative paragraph.
3. Close the briefing document.
*Wait, one constraint:* "Do not include disclaimers about being an AI." "Do not speculate beyond what the data shows."
My draft is based on the data (Risk score 40, DNSBL 2, Subnet clean, etc.).
*Let's finalize the text.*
address exhibits a moderate risk score of 40, primarily driven by dynamic residential classification and DNSBL listings rather than active malicious infrastructure. The subnet 103.170.55.0/24 maintains a clean classification with zero active threat siblings, indicating localized rather than systemic risk. Historical data shows no persistent malicious activity or ownership
address exhibits a moderate risk score of 40, primarily driven by dynamic residential classification and DNSBL listings rather than active malicious infrastructure. The subnet 103.170.55.0/24 maintains a clean classification with zero active threat siblings, indicating localized rather than systemic risk. Historical data shows no persistent malicious activity or ownership changes, consistent with typical residential ISP behavior. While the IP is currently firewalled with no open ports, the presence on two DNSBL lists warrants standard defensive posture. Analysts should correlate any inbound traffic from this source with internal logs to confirm benign or malicious intent before applying strict blocking rules, as the risk score is moderate rather than critical. Standard monitoring or blocking policies should be applied in accordance with organizational threat tolerance thresholds.
Status: Monitoring Recommended
Priority: Low to Moderate
Last Updated: July 28, 2026
End of Briefing.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | NAJEEB VS |
| ASN | AS138754 |
| Network Name | THRISSUR |
| CIDR Block | 103.170.54.0/23 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | keralavisionisp-dynamic-6.55.170.103.keralavisionisp.com |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | keralavisionisp-dynamic-6.55.170.103.keralavisionisp.com |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS138754 |
| Network Prefix | 103.170.55.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-18 05:29:03 UTC |
| Last Seen | 2026-09-02 22:54:43 UTC |
| Profile Built | 2026-09-02 22:56:46 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 103.170.55.6
Who owns the IP address 103.170.55.6?
103.170.55.6 is registered to NAJEEB VS. The address falls within the 103.170.54.0/23 network block. Registration is held at APNIC.
Where is 103.170.55.6 located?
Geolocation data places 103.170.55.6 in Kollam, Kerala, India. The local time zone is Asia/Kolkata. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 103.170.55.6 malicious or safe?
103.170.55.6 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 103.170.55.6?
The reverse DNS (PTR) record for 103.170.55.6 is keralavisionisp-dynamic-6.55.170.103.keralavisionisp.com. This hostname is not forward-confirmed, so it should be treated as a weak signal.