# IP INTELLIGENCE BRIEFING
Target: 103.174.102.42/32
Date: 2026-07-29
Classification: Moderate Risk (Score: 50/100)
---
## EXECUTIVE SUMMARY
IP 103.174.102.42 presents a moderate risk profile with no active threat indicators. The asset appears to be a firewalled infrastructure endpoint with minimal operator activity and no known malicious associations. Geolocation data shows conflicting signals requiring validation.
---
## OWNERSHIP & NETWORK CONTEXT
- ASN: 133719 (IDIGITAL / NOC ADMIN)
- Network: 103.174.102.0/23 (APNIC RIR)
- Classification: Infrastructure / Firewalled
- ISP: Provider infrastructure with minimal operator score (0.1304)
---
## THREAT INDICATORS
- Risk Score: 50/100 (Moderate)
- Blacklist Status: 2 DNSBL listings out of 8 total lists
- Known Campaigns: None identified
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Abuse Confidence: Not elevated
---
## GELOCATION INCONSISTENCY ALERT
Profile geolocation indicates US/New York, while historical observation data (2026-07-29 09:57:33 UTC) shows geolocation inference pointing to India (IN) with 0.52 confidence. This discrepancy warrants investigation and may indicate:
- Virtual/private hosting
- Misconfigured DNS/geo data
- Legitimate multi-region operations
---
## DNS & HOSTING
- Resolved Hostname: server1.wehear.in
- Email Authentication: SPF and DMARC configured
- Forward Resolution: Confirmed (1 hostname)
- Open Ports: None detected
- Services: Firewalled / No active services exposed
---
## NEIGHBORHOOD ANALYSIS
Subnet: 103.174.102.0/24
- Total Siblings: 3
- Active Siblings: 1
- Threat Siblings: 0
- Abuse Density: 0 (Clean)
- Neighbor Risk Scores:
- 103.174.102.136: 30/100 (Low)
- 103.174.102.204: 40/100 (Low)
---
## OBSERVATION HISTORY
- Total Observations: 17 signals
- Recent Activity: No persistent malicious behavior detected
- Threat Persistence: 0 days
- Ownership Changes: 0
- Route Stability: Stable (0 route changes in 30 days)
- Control Plane: RPKI validation pending, IRR consistency checkable
---
## RECOMMENDED ACTIONS
Current Risk Assessment: No immediate threat action required. However, the following controls are recommended:
| Platform | Action |
|---|---|
| iptables | `iptables -A INPUT -s 103.174.102.42 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 103.174.102.42 drop` |
| nginx | `deny 103.174.102.42;` |
| pfSense | Block 103.174.102.42/32 |
| Cloudflare WAF | Block IP with expression `ip.src eq 103.174.102.42` |
| AWS WAF | Add to allow/block list: 103.174.102.42/32 |
---
## ANALYST NOTES
1. Monitor Geolocation Discrepancy: The US vs India location conflict should be validated through additional passive DNS or traceroute analysis.
2. No Active Threats: The IP has no known malicious associations. Firewall rules are probabilistic recommendations and should be reviewed against other intelligence.
3. Neighborhood Clean: The /24 subnet shows minimal abuse density with only 1 active sibling.
4. Email Infrastructure: The associated domain (wehear.in) has proper SPF/DMARC configuration, suggesting legitimate email hosting use case.
---
Status: MONITOR (No immediate blocking required)
Priority: LOW
Next Review: Recommended within 7-14 days or upon threat indicator escalation
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | NOC ADMIN |
| ASN | AS133719 |
| Network Name | IDIGITAL |
| CIDR Block | 103.174.102.0/23 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | server1.wehear.in |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | server1.wehear.in |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-21 19:02:23 UTC |
| Last Seen | 2026-08-13 06:43:20 UTC |
| Profile Built | 2026-08-08 01:30:22 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 21 |
Full dossier details are available via our API.