# IP Intelligence Briefing: 103.26.83.61
Classification: Low Risk / Monitoring Required
Date: 2026-07-25
Analyst: IPDebrief Intelligence Unit
## Executive Summary
IP 103.26.83.61 is a low-risk infrastructure address assigned to CYBERNET-PK (ASN 9541), a Pakistan-based hosting provider. The address shows minimal threat indicators with a risk score of 25/100. No active malicious behavior observed. However, the address is listed on 1 of 8 DNSBLs with high severity, and a neighboring IP (103.26.83.93) presents elevated risk (score 40/100).
## Ownership & Geolocation
| Attribute | Value |
|---|---|
| **ASN** | 9541 |
| **Organization** | CYBERNET-PK (Amjad Qasmi) |
| **Location** | Karachi, Sindh, Pakistan (PK) |
| **CIDR Block** | 103.26.82.0/23 |
| **Registration** | APNIC RIR |
## Risk Profile
- Overall Risk Score: 25 (Low Risk)
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
- DNSBL Listings: 1/8 lists (high severity)
- Operator Score: 0
## Threat Indicators
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0
- Campaign Correlation: None detected
- Honeypot Hits: 0
- Active Attacker Status: No
## Network Services
- Open Ports: None detected
- Service Classification: Firewalled / No Services
- TLS Certificate: Not observed
- HTTP Banner: Not observed
- DNS Resolution: PTR record absent; forward resolution count: 0
## Control Plane Analysis
- BGP Prefix: 103.26.83.0/24
- Route Stability: Unstable
- DNSSEC Validation: Valid
- Route Changes (30d): 0
- MOAS Status: No
- IRR Consistency: Not assessed
## Neighborhood Assessment
Subnet: 103.26.83.0/24
- Abuse Density: 0
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 0
Notable Neighbor: 103.26.83.93
- Risk Score: 40 (Medium Risk)
- Authority Score: 50
- Classification: Requires monitoring
## Observation History
Ten signals observed over the monitoring period. Key recent activity includes:
- DNSSEC validation confirmed (2026-07-25)
- ASN information verified (CYBERNET-PK, allocated 2013-06-19)
- One DNSBL listing detected with high severity classification
- No ownership changes recorded
- Threat persistence: 0 days
## Relationship Graph
Three relationships identified, all pointing to the same network entity:
- CYBERNET-PK (Same Network)
## Recommended Actions
| System | Recommendation |
|---|---|
| **Firewall** | No immediate blocking required. Monitor for traffic pattern changes. |
| **IDS/IPS** | No signature-based rules recommended. |
| **SIEM** | Log traffic for baseline comparison. |
| **WAF** | No specific rules generated. |
Note: Recommendations are probabilistic and should be combined with other signals before taking action.
## Intelligence Narrative
IP 103.26.83.61 presents as a legitimate infrastructure address within the CYBERNET-PK hosting network in Pakistan. The absence of open ports and services suggests the address may be used for internal infrastructure, residential proxying, or residential hosting services. The single DNSBL listing with high severity warrants awareness but does not indicate active malicious activity from this specific address.
The neighborhood analysis indicates low abuse density within the /24 subnet. However, the presence of neighbor 103.26.83.93 at medium risk level (40/100) suggests potential correlation with other infrastructure in this network segment that may require additional scrutiny.
SOC Analyst Guidance: No immediate blocking action required. Include in monitoring baselines. Investigate if traffic from this address correlates with suspicious events. Monitor for any changes in service status or threat indicators.
---
Data Sources: IPDebrief Intelligence Platform
Confidence Level: High
Last Updated: 2026-07-25 15:11:19 UTC
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Amjad Qasmi |
| ASN | AS9541 |
| Network Name | CYBERNET-PK |
| CIDR Block | 103.26.82.0/23 |
| RIR | APNIC |
| Country | PK |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS9541 |
| Network Prefix | 103.26.80.0/22 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 12% | 2 | 2 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 17% | 2 | 3 |
| reputation | 8% | 1 | 2 |
| geolocation | 8% | 1 | 1 |
| Overall | 10% | 8 | 10 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-09 19:39:14 UTC |
| Last Seen | 2026-10-05 00:25:51 UTC |
| Profile Built | 2026-10-05 00:27:51 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 23 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 103.26.83.61
Who owns the IP address 103.26.83.61?
103.26.83.61 is registered to Amjad Qasmi. The address falls within the 103.26.82.0/23 network block. Registration is held at APNIC.
Where is 103.26.83.61 located?
Geolocation data places 103.26.83.61 in Marseille, Sindh, France. The local time zone is Europe/Paris. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 103.26.83.61 malicious or safe?
103.26.83.61 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.