# IP INTELLIGENCE BRIEFING
Target: 103.173.51.155/32
Classification: High Risk (Score: 70/100)
Report Date: Current
Data Source: IPDebrief Intelligence Platform
---
## EXECUTIVE SUMMARY
IP 103.173.51.155 is classified as High Risk with a reputation score of 70/100. The address is associated with ASN 137109 (NOC ADMIN, SHAURAY) in India and operates as a single-service host with HTTP service exposure on port 80. Despite elevated risk scoring, no active threat indicators or malicious activity were observed in recent signal history.
---
## TECHNICAL PROFILE
Network Ownership
| Field | Value |
|---|---|
| ASN | 137109 |
| Organization | NOC ADMIN |
| Network Name | SHAURAY |
| CIDR Block | 103.173.50.0/23 |
| RIR | APNIC |
Geolocation & Routing
- Country: India (IN)
- Traceroute: 19 hops (4 timed out), transit via Comcast
- Route Stability: Unstable (isRouteStable: false)
- MoAS: No
- RPKI State: Unavailable
Network Role
- Classification: Single-Service Host
- Services: HTTP (TCP/80)
- Infrastructure Type: Not CDN, Cloud, VPN, Proxy, Tor, or Anycast
- DNS Resolution: Forward resolution not confirmed
---
## THREAT ASSESSMENT
Risk Indicators
- DNSBL Listings: 4 of 8 lists (dnsblListedCount: 4)
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Campaign Association: None
Behavioral Analysis
- Honeypot Hits: 0
- Enumeration Strikes: 0
- Threat Observation Count: 0
- Persistently Malicious: No
- Threat Persistence Days: 0
---
## OBSERVATION HISTORY
Analysis of 18 signal observations reveals the following temporal patterns:
- Subnet Classification: Consistently classified as "clean" with zero inherited risk
- Ownership Stability: No ownership changes detected
- Network Role: Consistently identified as non-hosting/non-cloud infrastructure
- Traceroute Validation: Successfully reached target through 19-hop path
No evidence of escalating threat activity or persistent malicious behavior observed.
---
## NETWORK RELATIONSHIPS
- Same Network: SHAURAY (103.173.51.0/24)
- Related Entities: 5 relationships identified, all network-level associations
- Correlated IPs: 0
---
## SUBNET ANALYSIS
- Subnet: 103.173.51.0/24
- Abuse Density: 0%
- Total Siblings: 0
- Active Siblings: 0
- Threat Siblings: 0
- Risk Distribution: High (0), Medium (0), Low (0)
No neighboring IPs showing abuse patterns; subnet appears isolated from broader abuse campaigns.
---
## RECOMMENDED ACTIONS
Immediate Mitigation
| Platform | Action |
|---|---|
| iptables | `iptables -A INPUT -s 103.173.51.155 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 103.173.51.155 drop` |
| nginx | `deny 103.173.51.155;` |
| pfSense | Block 103.173.51.155/32 |
| Cloudflare WAF | Block (expression: ip.src eq 103.173.51.155) |
| AWS WAF | Add 103.173.51.155/32 to blacklist |
Monitoring Enhancements
- Increase logging verbosity for this IP
- Review recent activity from source IP
- Monitor for any changes in service banner or behavior
---
## ANALYST NOTES
The elevated risk score (70/100) appears to be conservative or based on historical DNSBL listings. Current signal observations show clean classification with no active threat indicators. However, the risk score warrants defensive posture and monitoring. The IP's classification as a single-service host with HTTP exposure suggests potential for web-based scanning or exploitation attempts.
Confidence Level: Medium
Threat Status: Elevated Risk / Monitor
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | NOC ADMIN |
| ASN | AS137109 |
| Network Name | SHAURAY |
| CIDR Block | 103.173.50.0/23 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| Closed Ports | 22, 25, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 25% | 1 | 2 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 8% | 2 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-25 08:44:25 UTC |
| Last Seen | 2026-08-13 12:52:06 UTC |
| Profile Built | 2026-07-30 02:42:12 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.