## Intelligence Briefing: IP Address 103.18.166.87/32
Classification: HIGH RISK THREAT INDICATOR
Report Date: [Current Date]
Intel Source: IPDebrief Network Intelligence Platform
---
Executive Summary
IP address 103.18.166.87 is classified as HIGH RISK with a risk score of 80/100. The address belongs to ASN 132768 (IRT-APNANET4-IN) and is located in India (IN). While currently firewalled with no active services, the IP demonstrates persistent threat activity with multiple blacklist listings and is associated with a subnet showing elevated abuse density (0.4741).
Technical Profile
- ASN: 132768 (IRT-APNANET4-IN)
- Network Block: 103.18.166.0/24
- Geolocation: India (IN) โ Regional: Newark (data inconsistency noted)
- Service Status: Firewalled / No Services detected
- DNS Classification: No reverse DNS resolution; no forward resolution
- Open Ports: None detected
- TLS/Certificates: None observed
Threat Indicators
- Blacklist Status: Listed on 4 of 8 DNSBLs (4 DNSBL listings total)
- Threat Feeds: Multiple blacklist indicators present
- Campaign Association: No known campaign matches identified
- Tor Exit Node: No
- Known Attacker: No explicit flag, but high-risk classification applies
Neighborhood Analysis (103.18.166.0/24)
The IP resides within a subnet of 116 sibling addresses with concerning characteristics:
- Abuse Density: 0.4741 (elevated)
- Threat Siblings: 55 IPs flagged as threats
- Active Siblings: 34 IPs currently active
- Risk Distribution: 2 high-risk, 83 medium-risk, 11 low-risk
- Classification: Mixed-use subnet with significant threat presence
Observation History
The IP has generated 17 signal observations, with recent activity detected on 2026-06-26. Historical data indicates:
- Recent Listing Activity: 8 total blacklist listings observed, with 2 current listings at "high" severity
- Persistence: Single threat observation recorded; not persistently malicious
- Route Stability: BGP routing changes detected within the last 30 days
Recommended Actions
Based on the high-risk profile and neighborhood context, the following defensive measures are recommended:
1. Firewall Rules: Implement block rules for 103.18.166.0/24 at perimeter firewall level
2. IDS/IPS Signatures: Deploy detection rules for traffic patterns from this subnet
3. Monitoring: Add 103.18.166.87 to threat intelligence feed watchlists
4. Email Filtering: Block connections from this IP range to prevent phishing/spam sources
Risk Assessment
This IP represents a moderate-to-high threat due to its blacklist associations and subnet-level abuse density. While the target IP itself shows no active services (firewalled), the surrounding subnet demonstrates elevated threat activity. SOC teams should consider blocking the entire /24 subnet as a defensive posture measure.
---
*Intel generated by IPDebrief Network Intelligence Platform for defensive security purposes.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-APNANET4-IN |
| ASN | AS132768 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 20% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Fresh
| First Seen | 2026-05-12 03:42:17 UTC |
| Last Seen | 2026-06-26 14:25:46 UTC |
| Profile Built | 2026-06-27 07:32:02 UTC |
| Data Freshness | Fresh |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.