# IP Intelligence Briefing: 103.38.204.165/32
## Executive Summary
IP address 103.38.204.165 presents a moderate risk profile (score: 50) with no active threat indicators. The address is associated with Rutul Shah under the GUJARATKUTCHNETWORK organization, located in Jลซnฤgadh, Gujarat, India. While currently classified as "clean" with zero active threat siblings, the presence on 2 of 8 DNSBL lists warrants monitoring. Recommended defensive action: block at perimeter firewall.
---
## Profile Overview
| Attribute | Value |
|---|---|
| **Risk Score** | 50 (Moderate) |
| **ASN** | 45916 |
| **Organization** | Rutul Shah |
| **Netname** | GUJARATKUTCHNETWORK |
| **Country** | India (IN) |
| **Region** | Gujarat |
| **City** | Jลซnฤgadh |
| **CIDR Block** | 103.38.204.0/22 |
| **Service Status** | Firewalled / No Services |
| **DNSBL Listed** | 2 of 8 |
---
## Threat Assessment
Current Status: No active malicious activity detected.
Threat Indicators:
- Not classified as Tor exit, known attacker, or spam source
- No known campaigns associated
- Zero threat observation count in historical data
- Not persistently malicious
Network Role:
- No open ports detected
- No TLS certificates or HTTP services
- Infrastructure type: undetermined
- Not identified as cloud, CDN, VPN, proxy, or hosting infrastructure
---
## Neighborhood Analysis (103.38.204.0/24)
- Abuse Density: 0 (clean)
- Total Siblings: 2
- Active Siblings: 1
- Threat Siblings: 0
- Neighbor IP: 103.38.204.143 (Risk Score: 25)
The /24 subnet exhibits low abuse density with minimal inherited risk. No sibling IPs show elevated threat activity.
---
## Observation History
Analysis of 13 signal observations reveals:
- Classification: "clean" with inherited risk: 0
- Operator Score: 0.1304 (Minimal)
- DNSSEC: Valid
- Geo signals consistently indicate India location with moderate confidence
- No ownership changes detected
- No threat persistence patterns observed
---
## Recommended Defensive Actions
Based on risk score of 50, the following firewall rules are recommended:
| Platform | Rule |
|---|---|
| **iptables** | `iptables -A INPUT -s 103.38.204.165 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 103.38.204.165 drop` |
| **nginx** | `deny 103.38.204.165;` |
| **pfSense** | `103.38.204.165/32` |
| **Cloudflare WAF** | Block IP (expression: `ip.src eq 103.38.204.165`) |
| **AWS WAF** | Add 103.38.204.165/32 to IP set with description "IPDebrief risk 50" |
---
## Intelligence Narrative
The target IP 103.38.204.165 operates from the GUJARATKUTCHNETWORK infrastructure in Gujarat, India. Despite moderate risk scoring, current observations show no active exploit attempts, port scans, or service exposure. The address appears to be firewall-protected with no accessible services. However, the presence on multiple DNSBL lists suggests prior reputation issues or association with previously flagged activity. The immediate neighborhood shows minimal abuse density, indicating this IP does not operate in a high-abuse subnet.
Threat Level: Moderate
Priority: Monitor and block at perimeter
Recommended Action: Implement firewall block per rules above; continue monitoring for escalation in threat signals.
---
*Report generated: 2026-07-30*
*Source: IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Rutul Shah |
| ASN | AS45916 |
| Network Name | GUJARATKUTCHNETWORK |
| CIDR Block | 103.38.204.0/22 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 2 |
| routing | 22% | 1 | 1 |
| services | 32% | 2 | 2 |
| ownership | 45% | 2 | 3 |
| reputation | 23% | 1 | 2 |
| geolocation | 46% | 2 | 3 |
| Overall | 33% | 10 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 09:38:34 UTC |
| Last Seen | 2026-07-31 07:29:44 UTC |
| Profile Built | 2026-07-30 17:10:03 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 18 |
Full dossier details are available via our API.