# IP Intelligence Briefing: 103.208.105.117/32
## Executive Summary
The IP address 103.208.105.117 is classified as Low Risk with a risk score of 0. No active threat indicators, malware campaigns, or known attacker associations have been identified. The IP is currently firewalled with no open services.
## Profile Assessment
- Risk Score: 0 (Low Risk)
- Reputation: Low Risk
- Network Role: Firewalled / No Services
- Threat Indicators: None detected
- Blacklist Status: Clean (0 listings)
- Tor/Proxy: Not identified as Tor exit node, proxy, or VPN
## Geolocation & Infrastructure
- Country: India (IN) - Confidence: 70%
- Coordinates: 21.9974° N, 79.0011° E
- ASN: 24186
- BGP Prefix: 103.208.105.0/24
- Route Stability: Unstable (isRouteStable: false)
- Operator Score: 0.1304 (Minimal)
## DNS & Services Analysis
- PTR Resolution: None detected
- Open Ports: None
- TLS Certificate: Not present
- DNSSEC: Valid
- DNSBL Listings: 0 active listings (8 total reference lists)
## Behavioral Indicators
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: 0
- Active Attacker: No
- Auto-Banned: No
## Observation History (7 observations recorded)
Recent signals from 2026-07-25 indicate:
- Geolocation: India (confidence 70%)
- Operator Score: 0.15 (Minimal)
- DNSSEC Validation: Active (confidence 90%)
## Network Neighborhood Assessment
- Subnet: 103.208.105.0/24
- Abuse Density: 0 (Minimal)
- Total Siblings: 2
- Risk Distribution: 1 Low, 0 Medium, 0 High
- Neighbor IPs:
- 103.208.105.54 (Risk: Null)
- 103.208.105.242 (Risk: 0, Authority: 50)
## Relationship Graph
No external relationships detected (subnets, hostnames, organizations, or certificates).
## Recommended Actions
No security actions recommended. The IP presents no immediate threat to network security.
## Threat Intelligence Narrative
The IP 103.208.105.117 represents a low-risk network endpoint with no observable malicious activity. Infrastructure analysis shows the address is actively firewalled with no open services, eliminating exploit surface opportunities. The subnet (103.208.105.0/24) exhibits minimal abuse density and contains only one additional active sibling IP. No campaign associations, known attacker signatures, or threat feed matches have been identified. Historical monitoring shows consistent low-risk behavior with no escalation patterns. The IP is suitable for standard network traffic handling without special filtering or blocking measures.
---
*Report generated for SOC intelligence purposes. Data sourced from IPDebrief threat intelligence platform.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Network Administrator |
| ASN | AS24186 |
| Network Name | RAILTEL-IN |
| CIDR Block | 103.208.104.0/22 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS24186 |
| Network Prefix | 103.208.105.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-09 13:30:49 UTC |
| Last Seen | 2026-08-30 09:24:39 UTC |
| Profile Built | 2026-08-29 05:54:51 UTC |
| Data Freshness | Live |
| Signal Types | 14 |
| Total Observations | 16 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 103.208.105.117
Who owns the IP address 103.208.105.117?
103.208.105.117 is registered to Network Administrator. The address falls within the 103.208.104.0/22 network block. Registration is held at APNIC.
Where is 103.208.105.117 located?
Geolocation data places 103.208.105.117 in East Kidwai Nagar, New, India. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 103.208.105.117 malicious or safe?
103.208.105.117 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.