# INTELLIGENCE BRIEFING: 103.39.247.141
## EXECUTIVE SUMMARY
IP address 103.39.247.141 presents moderate risk (score: 55) with no active threat indicators. The IP belongs to infrastructure under IRT-WEBSTAR-IN (ASN: 133720), registered with APNIC in India (Maharashtra, Ulhasnagar). The address is currently firewalled with no active services. While the IP itself shows no malicious activity, it appears on 3 out of 8 DNSBLs, suggesting historical reputation concerns.
---
## NETWORK OWNERSHIP & CLASSIFICATION
| Attribute | Value |
|---|---|
| ASN | 133720 |
| Organization | IRT-WEBSTAR-IN |
| Network Name | WEBSTAR |
| CIDR Block | 103.39.247.0/24 |
| RIR | APNIC |
| Country | India (IN) |
| Region | Maharashtra |
| City | Ulhasnagar |
Network Role: Infrastructure provider with firewalled configuration. No CDN, cloud, VPN, proxy, or hosting services detected. Not classified as bogon, mobile, residential, or Tor exit node.
---
## THREAT PROFILE
| Indicator | Status |
|---|---|
| Known Attacker | No |
| Tor Exit Node | No |
| Spam Source | No |
| Active Threat Indicators | None |
| Known Campaigns | None |
| Blacklist Count | 0 |
| DNSBL Listings | 3 of 8 total lists |
Risk Assessment: Moderate risk score (55/100) driven primarily by DNSBL presence rather than active malicious behavior. No evidence of persistence or campaign association.
---
## INFRASTRUCTURE ANALYSIS
DNS Resolution:
- PTR Hostname: 103.39.247.141.zessnetworks.com
- Forward Confirmation: Failed
- Hosted Domains: 0
- Email Authentication: SPF and DMARC configured
Services:
- Open Ports: None detected
- TLS Certificate: None
- HTTP Title: None
- Server Banner: None
Control Plane:
- BGP Prefix: 103.39.247.0/24
- Origin ASN: 133720
- Route Stability: False (route changes detected)
- RPKI State: Not validated
- DNSSEC: Valid
---
## OBSERVATION HISTORY
17 signal observations recorded, most recent: 2026-07-27. Historical signals show consistent network ownership with no ownership changes. Geolocation signals validate the India/Maharashtra location assignment. No persistent malicious activity detected in the observation window.
---
## NEIGHBORHOOD ANALYSIS
Subnet: 103.39.247.0/24
- Abuse Density: 0% (clean)
- Active Siblings: 0
- Threat Siblings: 0
- Classification: Clean
The IP resides in a low-abuse subnet with no neighboring IPs flagged for malicious activity.
---
## RELATIONSHIP MAPPING
8 relationships identified:
- 3 Same Network associations (WEBSTAR)
- 5 DNS Association entries (103.39.247.141.zessnetworks.com)
No associations to external organizations, hostnames beyond the PTR record, or certificates.
---
## ACTIONS & RECOMMENDATIONS
Based on the moderate risk score and DNSBL presence:
1. Monitor: Track for service activation and DNSBL status changes
2. Block: Consider blocking at network perimeter if traffic patterns suggest abuse
3. Investigate: Review inbound traffic for potential reputation-based filtering issues
4. No Immediate Threat: No active malicious indicators requiring immediate containment
---
Analyst Note: This IP represents infrastructure-level presence with historical reputation concerns but no current active threat indicators. The moderate risk score warrants monitoring rather than immediate blocking actions.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-WEBSTAR-IN |
| ASN | AS133720 |
| Network Name | WEBSTAR |
| CIDR Block | 103.39.244.0/22 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 103.39.247.141.zessnetworks.com |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 103.39.247.141.zessnetworks.com |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS133720 |
| Network Prefix | 103.39.247.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 18% | 5 | 5 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-13 09:16:41 UTC |
| Last Seen | 2026-08-31 21:52:11 UTC |
| Profile Built | 2026-08-31 21:57:40 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 27 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 103.39.247.141
Who owns the IP address 103.39.247.141?
103.39.247.141 is registered to IRT-WEBSTAR-IN. The address falls within the 103.39.244.0/22 network block. Registration is held at APNIC.
Where is 103.39.247.141 located?
Geolocation data places 103.39.247.141 in Ulhasnagar, Maharashtra, India. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 103.39.247.141 malicious or safe?
103.39.247.141 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 103.39.247.141?
The reverse DNS (PTR) record for 103.39.247.141 is 103.39.247.141.zessnetworks.com. This hostname is not forward-confirmed, so it should be treated as a weak signal.