# IP Intelligence Briefing: 103.226.4.118/32
Classification: Moderate Risk
Risk Score: 40/100
Date of Analysis: 2026-07-30
---
## Executive Summary
IP address 103.226.4.118 is associated with ASN 58678 and the APNIC RIR registry. The IP presents moderate risk (40) with evidence of DNSBL listings on 2 of 8 total blacklists. Network scans indicate no open services; the IP is currently firewalled. The IP belongs to the 103.226.4.0/24 subnet with a sibling IP (103.226.4.113) showing identical risk characteristics.
## Ownership and Geolocation
Organization: IRT-IN-GOAIR
Abuse Contact: noc@intechonline.net
Country: India (Maharashtra, Latur)
ASN: 58678
BGP Prefix: 103.226.4.0/24
The IP's registration data indicates association with an Indian organization. Geolocation data places the address in Latur, Maharashtra.
## Threat Indicators
| Indicator | Status |
|---|---|
| DNSBL Listed | Yes (2/8 lists) |
| Known Attacker | No |
| Tor Exit Node | No |
| Spam Source | No |
| Blacklist Count | 0 (primary profile) |
| Risk Score | 40 |
Note: Discrepancy exists between profile blacklist count (0) and control plane DNSBL data (2/8 lists). Control plane data should be weighted higher for threat assessment.
## Network Behavior
- Services: No open ports detected
- Network Role: Firewalled / No Services
- Route Stability: False (instability detected)
- RPKI State: Not assessed
- Behavioral Flags: No active attacker, no honeypot hits, no WAF violations
## Neighborhood Analysis (103.226.4.0/24)
The /24 subnet contains 2 sibling IPs with the following risk distribution:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 103.226.4.38 | 0 | 50 |
| 103.226.4.113 | 40 | 50 |
Abuse Density: 0
Classification: No inherited risk from subnet
The presence of a sibling IP (103.226.4.113) with matching risk score (40) and authority score (50) suggests coordinated infrastructure or shared hosting environment.
## Observation History
Nine observations recorded. Most recent signal (2026-07-30) confirms:
- Organization: IRT-IN-GOAIR
- RIR: APNIC
- Abuse email: noc@intechonline.net
- Geolocation: Latur, Maharashtra, India
Historical data indicates consistent ownership signals with no significant changes.
## Recommended Actions
Based on risk score of 40 and DNSBL presence, the following blocking measures are recommended:
```bash
# iptables
iptables -A INPUT -s 103.226.4.118 -j DROP
# nftables
nft add rule inet filter input ip saddr 103.226.4.118 drop
# nginx
deny 103.226.4.118;
# Cloudflare WAF
Filter: ip.src eq 103.226.4.118
Action: block
# AWS WAF
Addresses: 103.226.4.118/32
```
Recommendation: Block at perimeter firewall or WAF level. Monitor for correlation with 103.226.4.113 which shares identical risk profile.
---
Analyst Notes: While the IP lacks active threat indicators and shows no open services, the DNSBL presence and route instability warrant monitoring. The subnet-level analysis suggests this may be part of a larger infrastructure requiring coordinated assessment.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-IN-GOAIR |
| ASN | AS58678 |
| Network Name | GOAIR-GO |
| CIDR Block | 103.226.4.0/24 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 15:45:54 UTC |
| Last Seen | 2026-07-30 12:19:47 UTC |
| Profile Built | 2026-07-30 12:34:11 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.