# IP INTELLIGENCE BRIEFING
Target: 103.204.209.9/32
Classification: Moderate Risk (Score: 40)
Date: July 30, 2026
---
## EXECUTIVE SUMMARY
IP address 103.204.209.9 belongs to Level3 Carrier Limited (ASN 58682) in Dhaka, Bangladesh. The IP presents moderate risk with no confirmed malicious activity detected. The IP is currently firewalled with no open services. Neighborhood analysis shows a clean subnet with minimal abuse density.
---
## OWNERSHIP & GEOLOCATION
| Attribute | Value |
|---|---|
| ASN | 58682 |
| Organization | Level3 Carrier Limited |
| Netname | LEVEL3-USER |
| RIR | APNIC |
| Country | Bangladesh (BD) |
| City | Dhaka |
| CIDR Block | 103.204.209.0/24 |
DNS Resolution: 9.209.204.103-level3carrier.net (forward confirmation: false)
Email Auth: No SPF/DMARC records configured
---
## THREAT ASSESSMENT
Risk Indicators:
- No active threat indicators
- Not a Tor exit node
- Not a known attacker or spam source
- Blacklist count: 0
- Known campaigns: None
- Threat observation count: 0
- Persistently malicious: False
Control Plane Status:
- Route stability: False
- Operator score: 0.1304 (Minimal)
- DNSBL listed: 2 of 8 total lists
- RPKI/IRR consistency: Not evaluated
---
## NETWORK ROLE & SERVICES
- Open ports: None detected
- Service purpose: Firewalled / No Services
- Infrastructure type: Not classified
- Cloud/CDN/VPN/Proxy: Not detected
- Anycast: Not detected
---
## NEIGHBORHOOD ANALYSIS (103.204.209.0/24)
| Metric | Value |
|---|---|
| Abuse density | 0 (Clean) |
| Total siblings | 4 |
| Active siblings | 2 |
| Threat siblings | 0 |
Neighbor Risk Distribution:
- 103.204.209.58: Risk 40 (Medium)
- 103.204.209.59: Risk 25 (Low)
- 103.204.209.223: Risk 25 (Low)
Conclusion: Subnet classified as clean with minimal abuse density.
---
## OBSERVATION HISTORY
16 observations recorded since last analysis. Key findings:
- Consistent ownership (0 ownership changes)
- No threat persistence detected
- Geolocation validation: ICMP blocked, but geo-plausible
- Route changes in last 30 days: 0
---
## RECOMMENDED ACTIONS
Risk Score: 40
| Platform | Action |
|---|---|
| iptables | `iptables -A INPUT -s 103.204.209.9 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 103.204.209.9 drop` |
| nginx | `deny 103.204.209.9;` |
| pfSense | `103.204.209.9/32` |
| Cloudflare WAF | Block IP (risk score 40) |
| AWS WAF | Block address 103.204.209.9/32 |
---
## ANALYST NOTES
- The IP is associated with Level3 Carrier Limited, a legitimate ISP infrastructure.
- No open services detected; IP appears firewalled.
- No active threat indicators despite moderate risk score.
- Firewall rules recommended as precautionary measure based on risk score.
- Monitor for changes in neighborhood classification or service emergence.
Priority: LOW-MEDIUM
Recommendation: Block at perimeter firewall; no immediate threat indicators present.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Level3 Carrier Limited |
| ASN | AS58682 |
| Network Name | LEVEL3-USER |
| CIDR Block | 103.204.209.0/24 |
| RIR | APNIC |
| Country | BD |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 9.209.204.103-level3carrier.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 9.209.204.103-level3carrier.net |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 15:45:53 UTC |
| Last Seen | 2026-08-03 05:13:31 UTC |
| Profile Built | 2026-07-30 12:34:11 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.