# IPDEBRIEF THREAT INTELLIGENCE BRIEFING
Target: 103.30.80.226/32
Date: 2026-07-24
Classification: LOW RISK
---
## EXECUTIVE SUMMARY
IP address 103.30.80.226 is a low-risk residential/business IP located in Ludhiana, India (AS133661). The address shows no active threat indicators, no open services, and no blacklist associations. While the /24 subnet exhibits moderate abuse density (25%), the target IP itself remains clean with a risk score of 30. No immediate defensive action is recommended.
---
## NETWORK IDENTIFICATION
| Field | Value |
|---|---|
| **IP Address** | 103.30.80.226 |
| **ASN** | 133661 |
| **Organization** | IRT-APNANET4-IN |
| **Netname** | APNANET4-IN |
| **Country** | India (IN) |
| **Region** | Punjab (PB) |
| **City** | Ludhiana |
| **CIDR Block** | 103.30.80.0/22 |
| **RIR** | APNIC |
---
## THREAT ASSESSMENT
Overall Risk Score: 30 (Low Risk)
Threat Indicators:
- Blacklist Count: 0
- Known Campaign Associations: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Abuse Confidence Score: Not applicable
Network Role:
- Infrastructure Type: None
- Cloud Service: No
- CDN: No
- VPN/Proxy: No
- Hosting Provider: No
- Mobile: No
- Residential: Yes
- Bogon: No
DNS Reputation:
- DNSBL Listed: 2 of 8 total lists (minimal impact)
- Forward Resolution: Not confirmed
- PTR Records: None
---
## OBSERVATION HISTORY
Total Signals Observed: 12
Recent Activity (2026-07-24):
- Classification: Clean
- Subnet: 103.30.80.226/24
- Abuse Density: 0 (subnet-level)
- Ownership Stability: No changes detected
- Threat Persistence: None
Historical Trends:
- Ownership changes: 0
- Threat observation count: 0
- Persistently malicious: False
- Risk trajectory: Stable
---
## SUBNET ANALYSIS (103.30.80.0/24)
Abuse Density: 25% (Moderate)
Risk Distribution:
- High Risk (55-80): 4 IPs
- Medium Risk (30-55): 11 IPs
- Low Risk: 0 IPs
Notable High-Risk Neighbors:
- 103.30.80.54 (Risk: 80)
- 103.30.80.57 (Risk: 80)
- 103.30.80.82 (Risk: 80)
- 103.30.80.222 (Risk: 80)
Assessment: The target IP (103.30.80.226) is not associated with any threat siblings. The subnet contains multiple active IPs with varying risk profiles, but the target address remains isolated from known malicious activity.
---
## RELATIONSHIP MAPPING
Connected Entities: 3
- Type: Same Network (APNANET4-IN)
- No external hostnames, domains, or certificates detected
- No inter-IP associations beyond subnet
---
## SERVICES & PORTS
Open Ports: None detected
HTTP/HTTPS: No active services
TLS Certificates: None
HTTP Title: None
Service Classification: Firewalled / No Services
---
## RECOMMENDED ACTIONS
Current Risk Level: LOW
Recommended Actions:
- No immediate firewall rules required
- No blocking recommended
- Monitor subnet-level activity for correlation
Firewall Configuration: N/A (Risk score below threshold)
---
## SOC ANALYST NOTES
1. Threat Posture: This IP is not currently exhibiting malicious behavior. No threat indicators detected.
2. Subnet Context: The /24 subnet shows moderate abuse activity (25% density). Monitor high-risk neighbors (103.30.80.54, 57, 82, 222) separately if they trigger alerts.
3. Geolocation: Consistent India-based signals from multiple sources. No geolocation validation violations.
4. Persistence: No evidence of persistent malicious use. Ownership and classification stable.
5. Action Threshold: If this IP appears in logs, no immediate blocking is warranted. Consider monitoring for behavioral changes if traffic patterns suggest abuse.
Confidence Level: High (based on 12 historical observations and comprehensive profile)
---
*Report generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-APNANET4-IN |
| ASN | AS133661 |
| Network Name | APNANET4-IN |
| CIDR Block | 103.30.80.0/22 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
CN=76082af118aa9bd01c5a69f37a84095e, L=MUM, S=MH, C=IN was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.| SANs | None |
| Valid From | 1969-12-31T19:00:39+00:00 |
| Valid Until | 1972-12-30T19:00:39+00:00 (expired) |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 1095 days |
🛡️ Public Network Snapshot
| Origin ASN | AS133661 |
| Network Prefix | 103.30.80.0/22 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-08 00:50:05 UTC |
| Last Seen | 2026-08-26 17:39:08 UTC |
| Profile Built | 2026-08-29 07:46:50 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 103.30.80.226
Who owns the IP address 103.30.80.226?
103.30.80.226 is registered to IRT-APNANET4-IN. The address falls within the 103.30.80.0/22 network block. Registration is held at APNIC.
Where is 103.30.80.226 located?
Geolocation data places 103.30.80.226 in Ludhiana, PB, India. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 103.30.80.226 malicious or safe?
103.30.80.226 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 103.30.80.226?
Responsive ports observed on 103.30.80.226 include 80, 443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.