## IP Intelligence Briefing: 103.237.58.63
Classification: Moderate Risk (Score: 55/100) | Status: Active Monitoring Recommended
---
Executive Summary
IP 103.237.58.63 presents moderate risk characteristics with no active services detected. The address belongs to ICOM (ASN 134863), registered to Managing Director under APNIC. While the IP shows no active malicious indicators in current threat feeds, it maintains 3 DNSBL listings and exhibits geolocation inconsistencies requiring verification.
---
Network Ownership & Registration
| Field | Value |
|---|---|
| ASN | 134863 (ICOM) |
| Organization | Managing Director |
| RIR | APNIC |
| CIDR Block | 103.237.56.0/22 |
| Abuse Contact | Available via RDAP |
---
Geolocation Assessment
Primary Indication: India (IN)
Confidence: Moderate (0.52-0.70)
Geolocation signals show inconsistencies:
- MaxMind GeoLite2: India (21.9974°N, 79.0011°E)
- Multi-signal inference: India (20.59°N, 78.96°E)
- Some probes report US-MA Boston region
Assessment: Geolocation reliability flagged as implausible with 1500km accuracy radius. Multiple signal sources required for validation.
---
Threat Intelligence
Current Threat Indicators:
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Active Campaigns: None detected
- Blacklist Entries: 0 (but 3 DNSBL listings)
- Pulsedive Risk: Not available
Control Plane Observations:
- Route Stability: False
- RPKI State: Not verified
- BGP Prefix: 103.237.58.0/23
- Route Changes (30d): 0
---
Neighborhood Analysis
Subnet: 103.237.58.0/24 (20 sibling IPs analyzed)
| Risk Category | Count | Details |
|---|---|---|
| High Risk | 0 | None detected |
| Medium Risk | 10 | Risk scores 55-70 |
| Low Risk | 7 | Risk scores 0-15 |
Notable Siblings:
- 103.237.58.18, 103.237.58.22: Risk 70
- 103.237.58.11, 103.237.58.14, 103.237.58.80: Risk 55
Abuse Density: 0 (Subnet-level metric)
---
Service & Behavioral Analysis
Open Ports: None detected
HTTP/TLS Services: None detected
DNS Records: No PTR hostnames, forward resolution disabled
Email Authentication: SPF/DMARC not configured
Certificate Authority: No HTTPS certificates
Behavioral Indicators:
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: 0
---
Temporal Analysis
Observation History: 14 signals recorded
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Persistently Malicious: False
Recent Activity: Signals observed 2026-07-18 (within last 24 hours)
---
Recommended Security Actions
Immediate Actions:
1. Increase logging verbosity - Review recent activity from this IP
2. Firewall Consideration: Block at perimeter if risk warrants
Platform-Specific Rules:
```
# iptables
iptables -A INPUT -s 103.237.58.63 -j DROP
# nftables
nft add rule inet filter input ip saddr 103.237.58.63 drop
# pfSense
103.237.58.63/32 (block rule)
```
Context: Risk score of 55/100 with no active services suggests this IP may be part of a larger infrastructure. Blocking is recommended if internal traffic has been observed.
---
Intelligence Assessment
This IP represents a moderate-risk indicator with limited actionable threat data. The absence of open services suggests either:
- Legitimate server with aggressive firewalling
- Compromised host in dormant state
- Infrastructure component (relay, proxy) without web exposure
SOC Analyst Action Items:
- Monitor for traffic patterns consistent with command-and-control
- Verify geolocation claims against internal DNS logs
- Review /24 neighborhood for correlated activity
- Consider blocking if internal reconnaissance observed
Confidence Level: Medium (geolocation inconsistencies)
Priority: Monitor – Not immediate threat
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-ICOM-IN |
| ASN | AS134863 |
| Network Name | ICOM |
| CIDR Block | 103.237.56.0/22 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS134863 |
| Network Prefix | 103.237.58.0/23 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (65%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-06-11 09:02:08 UTC |
| Last Seen | 2026-09-29 20:34:28 UTC |
| Profile Built | 2026-09-29 20:35:55 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 23 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 103.237.58.63
Who owns the IP address 103.237.58.63?
103.237.58.63 is registered to IRT-ICOM-IN. The address falls within the 103.237.56.0/22 network block. Registration is held at APNIC.
Where is 103.237.58.63 located?
Geolocation data places 103.237.58.63 in Boston, US-MA, India. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 103.237.58.63 malicious or safe?
103.237.58.63 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.