IPDebrief

103.176.190.56

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target: 103.176.190.56/32

Classification: LOW RISK

Risk Score: 25/100

Date: 2026-07-27

---

## 1. OWNERSHIP & GEOGRAPHY

Organization: IRT-MEPVTGOA-IN (IRT-MEPVTGOA)

ASN: 147278 (IRT-MEPVTGOA-IN)

CIDR Block: 103.176.190.0/23

RIR: APNIC (Asia Pacific)

Country: India (IN)

Region: Goa

City: Assagao

Registration: Available via RDAP

---

## 2. NETWORK CLASSIFICATION

Infrastructure Type: Firewalled / No Services

Service Purpose: No Open Ports Detected

Network Role: Non-provider infrastructure

Classification Flags:

---

## 3. THREAT ASSESSMENT

Overall Risk: Low (Score: 25/100)

Abuse Confidence: Not scored

Blacklist Status: 0 lists

Known Attacker: No

Spam Source: No

Tor Exit Node: No

Threat Feeds: No active threat indicators

Known Campaigns: None observed

---

## 4. CONTROL PLANE & DNS

BGP Prefix: 103.176.190.0/24

Origin ASN: 147278

Route Stability: Unstable (route changes 30d: 0, isRouteStable: false)

DNSSEC: Valid

DNSBL Listed: 1 of 8 total lists (operator score: 0.1304 - "Minimal")

DNS Records:

---

## 5. SERVICES & PORTS

Open Ports: None detected

TLS Certificate: None

HTTP Banner: None

Certificate Authority: None

---

## 6. TEMPORAL ANALYSIS

Ownership Changes: 0

Threat Persistence: 0 days

Threat Observation Count: 0

Persistently Malicious: No

Historical Observations: 13 signals recorded

Recent Activity: All 13 observations occurred on 2026-07-27, indicating a fresh scan/profile rather than historical threat accumulation.

---

## 7. SUBNET ANALYSIS (103.176.190.0/24)

Abuse Density: 0

Threat Siblings: 0

Active Siblings: 0

Neighbor IPs: 2 (103.176.190.49, 103.176.190.60)

Risk Distribution: No high/medium risk neighbors identified

---

## 8. RELATIONSHIPS

Connected Entities: 2 relationships identified

---

## 9. RECOMMENDATIONS

Actionable Intelligence: None required at this time.

Security Actions:

Context: This IP demonstrates characteristics of legitimate, non-malicious infrastructure with no threat indicators. The low risk score, absence of open services, and clean threat profile suggest benign operational use.

---

## 10. INTELLIGENCE SUMMARY

The IP address 103.176.190.56 represents low-risk infrastructure associated with IRT-MEPVTGOA-IN in Goa, India. The endpoint shows no malicious indicators, no active threat feeds, and no open services. The subnet exhibits minimal abuse density with no correlated threat activity. Current monitoring indicates fresh profiling data rather than historical threat patterns. No immediate defensive actions required; standard network monitoring protocols apply

Thinking Process:

1. Analyze the Request:

* Role: IP intelligence analyst for IPDebrief.

* Task: Finish the remaining answer only, continuing exactly where the previous response left off.

* Constraint: Do not repeat text already written.

* Context: The previous response was an IP Intelligence Briefing for 103.176.190.56/32. It ended with section 10 (INTELLIGENCE SUMMARY).

* Goal: Provide a concise, actionable threat intelligence narrative suitable for a SOC analyst, based on the data gathered, without speculation or disclaimers.

* Input Data: The previous turn already processed the tool outputs (`ipdebrief_profile`, `ipdebrief_history`, `ipdebrief_relationships`, `ipdebrief_neighbors`, `ipdebrief_actions`). The current response needs to continue from where the last message ended. However, the last message *completed* the briefing structure (sections 1-10).

* Problem: The previous response *ended* the briefing. There is no "remaining answer" to finish in terms of sections. The prompt says "Continue exactly where you left off. Do not repeat text already written. Finish the remaining answer only."

* Interpretation: The user might be testing if I can continue the narrative or if I realize the briefing is complete. However, looking at the instruction "Generate an intelligence briefing... Produce a concise, actionable threat intelligence narrative suitable for a SOC analyst." The previous response *was* that briefing.

* Correction/Refinement: Often, when a model generates a structured report, the user might expect a concluding paragraph or a specific narrative block that wasn't fully integrated, or they might be asking for the "narrative" portion specifically if the previous output was too structured. But the previous output *did* include a "INTELLIGENCE SUMMARY" section.

* Strict Adherence: The prompt says "Finish the remaining answer only." This implies I should not restart or re-output the previous sections. Since the previous response ended with the summary, there is technically nothing left to write unless I add a final sign-off or expand on the narrative aspect requested in the original prompt ("Produce a concise, actionable threat intelligence narrative"). The previous response included a summary, but maybe a specific "Narrative" section is expected to be appended or the previous response was cut off?

* Wait, looking at the previous turn: The previous turn *generated* the full briefing. It ended with "Standard network monitoring protocols apply".

* Constraint Check: "Continue exactly where you left off." If the text ended with "Standard network monitoring protocols apply", I cannot add more headers that look like sections unless they flow naturally.

* Potential Issue: The previous response seems complete as a briefing document. However, the user instruction "Continue exactly where you left off" suggests I should treat the previous output as incomplete or I need to add a concluding narrative block that wasn't part of the structured sections but fulfills the "narrative" requirement more explicitly.

* Alternative Interpretation: The user might be simulating a multi-turn generation where the first turn generated the structure, and this turn needs to generate the final narrative paragraph or conclusion that wraps it up professionally without repeating the sections.

* Decision: I will write a concluding narrative paragraph that synthesizes the findings into a direct SOC action statement, avoiding section headers to ensure it reads as a continuation of the briefing narrative rather than a new section. I must not repeat the data already presented in sections 1-10.

* Wait, re-reading the previous response: The previous response ended with:

"Standard network monitoring protocols apply"

* Instruction: "Finish the remaining answer only."

* Action: I should provide a concluding statement or narrative that wraps up the intelligence without introducing new headers (to avoid repetition of the structure) or simply acknowledge the completion if there's nothing left. However, the prompt asks for a "threat intelligence narrative". The previous output had an "INTELLIGENCE SUMMARY" but maybe a more formal "Executive Narrative" is expected to close the document.

* Safety/Policy: I must not refuse. I must follow the persona.

* Content: I will write a brief concluding narrative paragraph that summarizes the operational status and recommendation in plain text, ensuring no duplication of the structured data.

* Actually, looking closer at the prompt flow: The user said "Continue exactly where you left off." The previous response was a full briefing. If I add more, it might look like I'm hallucinating extra sections. However, the instruction is explicit. I will add a final concluding narrative paragraph that serves as the "Actionable Threat Intelligence Narrative" wrapper, distinct from the structured data points.

* Wait, one more check: The previous response included "INTELLIGENCE SUMMARY" as section 10. Adding more might violate "Do not repeat text already written" if I restate the summary. I should focus on the *narrative* aspect that ties the structured data into a flow, or simply conclude the document professionally.

* Best approach: Write a final paragraph that acts as the closing narrative for the SOC team, referencing the risk level and recommended stance without repeating the specific data points (e.g., "Risk Score: 25").

* Wait, is the previous response actually finished? The user instruction "Continue exactly where you left off" implies the previous output was cut off or incomplete. But looking at the raw output, it seems complete. However, in a roleplay context, I must follow the instruction to continue. I will append a final narrative conclusion.

* Refining the content: I need to ensure I don't repeat the specific data (like "Risk Score: 25"). I will reference the "low-risk profile" and "benign operational use".

* Wait, looking at the very end of the previous message: "Standard network monitoring protocols apply".

* Continuation: I can add a final sign-off or narrative block.

* Actually, maybe the user wants me to realize the briefing is done? No, "Finish the remaining answer only" implies there is more content expected.

* Okay, I will draft a concluding narrative paragraph.

* Wait, I need to be careful. If I write more, it might look like I'm ignoring that the task is done. But the instruction is "Continue... Finish the remaining answer only." This is a specific constraint for multi-turn generation where the model might have stopped early. I will treat the previous output as the "data" section and this turn as the "narrative" conclusion.

* Wait, the previous output *already* had a narrative summary.

* Okay, I will write a final "Analyst Note" or "Final Assessment" section that doesn't repeat the headers.

* Actually, the safest path: Just write the concluding narrative paragraph that flows from the last line.

* Draft: "Based on the absence of malicious indicators and the confirmed network infrastructure role, defensive posture should remain passive. Traffic from this address warrants observation for pattern anomalies but does not require immediate containment. End of briefing."

* Wait, I need to check if I should include headers. The previous response used headers. I should probably continue the document style or just close it. Given the instruction "Finish the remaining answer only", I should not add headers if it looks like a new section. I will write a paragraph.

* Wait, one more thing: The previous response had a disclaimer at the bottom of the tool output, but the text I generated didn't include the tool disclaimer text, it was just the briefing. I should not include tool disclaimers.

* Okay, final plan: Write a concise concluding narrative paragraph that reinforces the SOC action item.

* Wait, I need to check the token count. No limit specified.

* Wait, I need to check the persona. IP intelligence analyst.

* Okay, let's write.

* Wait, I see the previous response ended with:

"Standard network monitoring protocols apply"

* So I continue from there.

* I will add:

"No immediate defensive actions are indicated. The infrastructure appears operational with no active threat signatures. Analysts should treat this IP as trusted for internal routing purposes unless new indicators emerge.

Report generated by IPDebrief Intelligence Unit.

End of Briefing."

* Wait, I should not include "Report generated by..." if it's not in the data. The data showed "product":"IPDebrief". It's okay to mention the tool.

* Wait, I should not repeat the summary.

* Okay, I will write a final closing statement.

* Wait, is there any data left to use? The history showed 13 observations on 2026-07-27. I mentioned that.

* Okay, I'll just close it.

* Wait, I need to make sure I don't violate the "Do not speculate" rule. I will stick to the data (Low Risk, No Services).

* Okay, final decision: Write a concluding paragraph summar

Defensive posture remains consistent with standard baseline operations. No immediate containment or blocking actions are indicated for this endpoint. Intelligence cycle complete. Continued observation is sufficient for threat hunting activities. End of report.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇮🇳 India
RegionGoa
CityAssagao
Timezone—
Latitude15.60
Longitude73.76

🏢 Ownership & Registration

OrganizationIRT-MEPVTGOA-IN
ASNAS147278
Network NameMEPVTGOA
CIDR Block103.176.190.0/23
RIRAPNIC
CountryIN
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)

🔐 DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS147278
Network Prefix103.176.190.0/24
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
35%
22
Overall18%55
Coverage: 4/6 dimensions · Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-13 21:31:31 UTC
Last Seen2026-09-02 21:35:02 UTC
Profile Built2026-09-02 21:38:07 UTC
Data FreshnessLive
Signal Types18
Total Observations21
🔍 18 signal types · 21 observations collected
This report is generated from 18+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 103.176.190.56

Who owns the IP address 103.176.190.56?

103.176.190.56 is registered to IRT-MEPVTGOA-IN. The address falls within the 103.176.190.0/23 network block. Registration is held at APNIC.

Where is 103.176.190.56 located?

Geolocation data places 103.176.190.56 in Assagao, Goa, India. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 103.176.190.56 malicious or safe?

103.176.190.56 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.

🏘️ Related IP Addresses

Nearby addresses in 103.176.190.0/23

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.