## IP Intelligence Briefing: 103.18.166.45/32
Classification: Moderate Risk | Risk Score: 55/100 | Date: 2026-06-22
---
Executive Summary
IP address 103.18.166.45 is a low-activity address within a high-density abuse neighborhood (103.18.166.0/24) with moderate risk characteristics. The IP presents no known direct threat indicators but requires monitoring due to elevated neighborhood abuse density and presence on 2 DNSBLs.
---
Ownership & Geolocation
- ASN: 132768
- Organization: IRT-APNANET4-IN
- Country: India (IN)
- City: Amritsar, Punjab
- BGP Prefix: 103.18.166.0/24
- Network Classification: Infrastructure (non-cloud, non-CDN, non-VPN)
---
Threat Assessment
Current Risk Level: Moderate (55/100)
Threat Indicators:
- No active threat signatures detected
- Not a known attacker or Tor exit node
- Not classified as spam source
- Blacklist count: 0 (direct IP)
- DNSBL listings: 2 of 8 total lists
Historical Context: 22 observations recorded over monitoring period. Recent activity shows stable ownership with no significant threat escalation. One observation flagged elevated blacklist severity (high).
---
Neighborhood Analysis
Subnet: 103.18.166.0/24
- Total Siblings: 123
- Active Siblings: 45
- Threat Siblings: 61
- Abuse Density: 0.4959 (moderate-high)
- Risk Distribution: High (7), Medium (78), Low (13)
Assessment: The IP resides in a mixed-use subnet with elevated abuse activity. 61 sibling IPs classified as threats, indicating potential infrastructure sharing or network-level risk factors.
---
Network Behavior
- Service Status: Firewalled / No Services
- Open Ports: None detected
- DNS Status: Forward confirmation failed; no PTR records
- Email Auth: SPF/DMARC not configured (no hosted domains)
- Control Plane: Route stability issues noted; RPKI state unavailable
---
Recommended Actions
Priority: Increase Monitoring (High Severity)
Firewall Actions:
- Block at perimeter: `iptables -A INPUT -s 103.18.166.45 -j DROP`
- Alternative rules available for nftables, nginx, pfSense, Cloudflare WAF, AWS WAF
Operational Recommendations:
1. Increase logging verbosity for traffic from this IP
2. Review recent connection activity and patterns
3. Monitor for changes in service state or behavior
4. Consider blocking subnet 103.18.166.0/24 if broader threat indicators emerge
---
Intelligence Notes
This IP shows characteristics of an infrastructure address with minimal direct threat indicators. However, the moderate risk score combined with elevated neighborhood abuse density warrants continued observation. No evidence of persistent malicious activity or campaign affiliation detected to date.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-APNANET4-IN |
| ASN | AS132768 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 41% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 23% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 24% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:26 UTC |
| Last Seen | 2026-06-22 06:46:37 UTC |
| Profile Built | 2026-06-22 06:55:24 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.