## IP Intelligence Briefing: 103.235.0.38/32
Classification: Moderate Risk | Date: 2026-07-25
---
Executive Summary
IP address 103.235.0.38 presents a moderate risk profile (score: 40/100) with no active threat indicators. The IP belongs to organization GAVIMERCANTILES within the 103.235.0.0/22 block, registered with ASN 137166 in Mumbai, India. Network activity is limited, with no open ports or active services detected.
Network Ownership & Geolocation
- Organization: GAVIMERCANTILES (manager admin)
- ASN: 137166
- CIDR Block: 103.235.0.0/22
- Geolocation: Mumbai, Maharashtra, India (IN)
- RIR: APNIC
- Geolocation Accuracy: ~1,500 km radius (multi-source consensus)
Risk Assessment
- Overall Risk Score: 40 (Moderate Risk)
- Abuse Confidence Score: Not applicable
- Blacklist Status: 0 blacklists (0 of 8 total lists)
- DNSBL Listed: 2 lists
- Operator Score: 0.1304 (Minimal)
- Is Known Attacker: No
- Is Tor Exit Node: No
- Is Spam Source: No
Technical Profile
- Network Role: Firewalled / No Services
- Open Ports: None detected
- TLS Certificates: None
- HTTP Services: None
- PTR Records: None
- Forward DNS Resolution: 0 records
- Hosted Domains: None
Neighborhood Analysis (103.235.0.0/24)
- Subnet Classification: Clean
- Abuse Density: 0 (clean)
- Total Siblings: 3
- Active Siblings: 0
- Threat Siblings: 0
- Neighbor IPs:
- 103.235.0.5: Risk Score 0
- 103.235.0.19: Risk Score null
No correlated threat activity observed within the /24 neighborhood.
Historical Observations
Thirteen observations recorded as of 2026-07-25, with no evidence of escalating threat behavior:
- Geolocation signals consistent across observations
- Ownership stability maintained (0 ownership changes)
- Threat persistence: 0 days
- Not classified as persistently malicious
- No campaign correlations detected
Control Plane & BGP
- Origin ASN: 137166
- BGP Prefix: 103.235.0.0/24
- Route Stability: Unstable (route changes detected in past 30 days)
- RPKI State: Not applicable
- DNSSEC Valid: Yes
Recommended Actions
Given the moderate risk score and absence of active threat indicators, implement the following:
| Platform | Recommended Action |
|---|---|
| iptables | `iptables -A INPUT -s 103.235.0.38 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 103.235.0.38 drop` |
| nginx | `deny 103.235.0.38;` |
| pfSense | Block 103.235.0.38/32 |
| Cloudflare WAF | Block with expression `ip.src eq 103.235.0.38` |
| AWS WAF | Add 103.235.0.38/32 to block list |
Intelligence Narrative
The IP 103.235.0.38 maintains a moderate risk posture without observable malicious activity. The absence of open ports, DNS services, or threat indicators suggests the address may be dormant, reserved, or used for legitimate purposes. The subnet exhibits clean characteristics with no abusive activity among sibling IPs. While the moderate risk score warrants attention, the lack of blacklist entries, zero threat indicators, and stable ownership history indicate this is not an active threat actor. Continued monitoring is recommended, particularly to observe any service activation or network behavior changes.
---
Briefing Prepared: 2026-07-25
Data Source: IPDebrief Intelligence Platform
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | manager admin |
| ASN | AS137166 |
| Network Name | GAVIMERCANTILES |
| CIDR Block | 103.235.0.0/22 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS137166 |
| Network Prefix | 103.235.0.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-10 01:47:36 UTC |
| Last Seen | 2026-08-26 17:35:54 UTC |
| Profile Built | 2026-08-29 07:47:08 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 17 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 103.235.0.38
Who owns the IP address 103.235.0.38?
103.235.0.38 is registered to manager admin. The address falls within the 103.235.0.0/22 network block. Registration is held at APNIC.
Where is 103.235.0.38 located?
Geolocation data places 103.235.0.38 in Mumbai, Maharashtra, India. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 103.235.0.38 malicious or safe?
103.235.0.38 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.