# IP Intelligence Briefing: 103.191.123.6/32
## Executive Summary
IP address 103.191.123.6 presents a Moderate Risk profile (Risk Score: 50/100) with no active threat indicators. The IP is currently firewalled with no open services, and belongs to a subnet with low abuse density (0.00). Recommended action: Block at perimeter firewall level due to DNSBL listings.
---
## Risk Assessment
| Metric | Value | Assessment |
|---|---|---|
| **Risk Score** | 50 | Moderate Risk |
| **Provider Score** | N/A | Data unavailable |
| **Authority Score** | N/A | Data unavailable |
| **Stability Score** | N/A | Data unavailable |
| **Abuse Confidence** | N/A | Not calculated |
| **DNSBL Listings** | 2 of 8 | Listed on multiple lists |
Threat Indicators: None active. IP is not identified as:
- Tor exit node
- Known attacker
- Spam source
- Active attacker
---
## Network Classification
| Attribute | Value |
|---|---|
| **Origin ASN** | 139043 |
| **BGP Prefix** | 103.191.123.0/24 |
| **Network Role** | Firewalled / No Services |
| **Infrastructure Type** | N/A |
| **Cloud/CDN/VPN** | Negative |
| **Hosting Provider** | Negative |
| **Mobile/Residential** | Negative |
Control Plane Status:
- Route stability: Unstable
- RPKI State: Not validated
- Route changes (30d): 0
- DNSSEC: Valid
- IRR Consistency: N/A
---
## Geolocation Data
No geolocation data available. The IP lacks PTR hostname resolution and forward DNS confirmation.
---
## Service & Port Analysis
- Open Ports: None detected
- TLS Certificate: None
- HTTP Banner: None
- DNS Records: No PTR hostnames, no forward resolution
The IP is currently firewalled with no accessible services.
---
## Historical Observations
Seven observation signals recorded, with the following key findings:
- Subnet Classification: Clean
- Inherited Risk: 1
- Total Siblings: 26
- Active Siblings: 23
- Threat Siblings: 1
The subnet 103.191.123.0/24 demonstrates low threat activity with only one threatening sibling IP.
---
## Neighborhood Analysis
Subnet: 103.191.123.0/24
- Neighbor Count: 25 siblings
- Abuse Density: 0 (low risk environment)
- Risk Distribution:
- High Risk: 0
- Medium Risk: 2
- Low Risk: 22
Notable Neighbors:
- 103.191.123.67: Risk Score 40
- 103.191.123.132: Risk Score 40
- Remaining neighbors: Risk Score 0-25
---
## Relationships
No relationships discovered (certificates, organizations, hostnames, or correlated subnets).
---
## Recommended Security Actions
Firewall Rules
```bash
# iptables
iptables -A INPUT -s 103.191.123.6 -j DROP
# nftables
nft add rule inet filter input ip saddr 103.191.123.6 drop
# pfSense
103.191.123.6/32
```
WAF Rules
Cloudflare WAF: Block with expression `ip.src eq 103.191.123.6`
AWS WAF: Addresses `103.191.123.6/32` with description "IPDebrief risk 50"
---
## Intelligence Narrative
The target IP 103.191.123.6 exhibits a moderate risk profile primarily driven by historical DNSBL listings (2 of 8 total lists) rather than active malicious behavior. The IP is currently firewalled with no open ports or services accessible. The surrounding subnet demonstrates a clean operational environment with only 1 of 26 sibling IPs flagged as threatening.
Despite the moderate risk score, no active attack campaigns, known malware distribution, or infrastructure-based threats have been identified. The absence of ASN, organization, or geolocation data limits attribution capabilities. The IP should be blocked at the perimeter level due to DNSBL presence, though the lack of active threat indicators suggests this is a precautionary measure rather than an immediate threat response.
---
*Report generated: IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Wali Telecom administrator |
| ASN | AS139043 |
| Network Name | WALITELECOM-PK |
| CIDR Block | 103.191.122.0/23 |
| RIR | APNIC |
| Country | PK |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 45% | 2 | 3 |
| routing | 22% | 1 | 1 |
| services | 32% | 2 | 2 |
| ownership | 47% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 23% | 1 | 1 |
| Overall | 32% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-28 16:13:30 UTC |
| Last Seen | 2026-08-01 04:24:31 UTC |
| Profile Built | 2026-07-30 23:15:33 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 19 |
Full dossier details are available via our API.