# IP Intelligence Briefing: 103.46.218.21
Classification: Low Risk Residential Endpoint
Date: 2026-07-24
Status: Active Monitoring
## Executive Summary
IP address 103.46.218.21 is a residential endpoint assigned to TAHITINUITELECOM-PF (ASN: 9471) in French Polynesia (PF). The IP carries a risk score of 25 (Low Risk) with no active threat indicators, blacklist entries, or known malicious activity. Historical observations show consistent residential classification with occasional threat signals detected in reputation feeds.
## Technical Profile
Ownership & Infrastructure:
- ASN: 9471 (IRT-TAHITINUITELECOM-PF)
- CIDR Block: 103.46.216.0/22
- Organization: TAHITINUITELECOM-PF
- Registration RIR: APNIC
- Abuse Contact: abuse@tnt.pf
Geolocation:
- Country: French Polynesia (PF)
- City: BP 111483 - Mahina
- Coordinates: -15°, -140°
- Classification: Residential Endpoint
Network Role:
- Infrastructure Type: Residential
- Connection Type: Residential
- Cloud/CDN/VPN/Proxy Status: Negative
- Mobile Carrier: Not detected
DNS Resolution:
- PTR Hostname: 03-web-shared.tnf.pf
- Forward Resolution: Confirmed
- Hosted Domains: None
## Threat Assessment
Current Threat Indicators: None detected
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Blacklist Count: 0
- DNSBL Listed: 1 (minor listing)
Risk Breakdown:
- Overall Risk Score: 25/100 (Low Risk)
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
## Historical Analysis
Fourteen observations recorded. Key temporal patterns observed:
1. 2026-07-24 15:43:42 — ASN and network ownership confirmed (confidence: 0.95)
2. 2026-07-24 15:43:58 — Geolocation signals from MaxMind GeoLite2 (confidence: 0.70)
3. 2026-07-24 15:44:15 — Residential infrastructure classification confirmed (confidence: 0.40)
4. 2026-07-24 15:44:32 — Reputation threat signals detected in AlienVault OTX (confidence: 0.75)
Threat persistence: 0 days. No evidence of persistent malicious behavior.
## Network Context
Neighborhood Analysis:
- Subnet: 103.46.218.21/24
- Neighboring IPs: 0
- Abuse Density: 0
- Threat Siblings: 0
Relationships:
- DNS Association: 03-web-shared.tnf.pf
- Network Association: TAHITINUITELECOM-PF
## Operational Recommendations
SOC Actions:
- No immediate blocking required due to low-risk classification
- Monitor for escalation in threat indicators
- Standard residential traffic policy applies
Firewall Rules:
- No specific rules recommended
- Allow traffic consistent with residential endpoint behavior
Risk Monitoring:
- Watch for DNSBL listing escalation
- Monitor for any changes in infrastructure classification
- Track for correlation with known campaigns
---
*Data Source: IPDebrief Intelligence Platform*
*Analysis Based On: Real-time IP Intelligence Services*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-TAHITINUITELECOM-PF |
| ASN | AS9471 |
| Network Name | TAHITINUITELECOM-PF |
| CIDR Block | 103.46.216.0/22 |
| RIR | APNIC |
| Country | PF |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 03-web-shared.tnf.pf |
| Forward Confirmed | Yes — FCrDNS verified |
| Forward Hostnames | 03-web-shared.tnf.pf |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Residential |
| Service Purpose | Web Server |
| Network Tier | End-User — Residential ISP endpoint |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | 2026-06-09T23:30:53+00:00 |
| Valid Until | 2027-06-09T23:30:53+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 365 days |
🛡️ Public Network Snapshot
| Origin ASN | AS9471 |
| Network Prefix | 103.46.218.0/23 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Enabled |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Mixed Signals (68%) — 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
⚠ TLS certificate claims CH but primary geo says PF
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-08 00:50:05 UTC |
| Last Seen | 2026-08-29 03:30:04 UTC |
| Profile Built | 2026-08-29 03:30:18 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 103.46.218.21
Who owns the IP address 103.46.218.21?
103.46.218.21 is registered to IRT-TAHITINUITELECOM-PF. The address falls within the 103.46.216.0/22 network block. Registration is held at APNIC.
Where is 103.46.218.21 located?
Geolocation data places 103.46.218.21 in PF. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 103.46.218.21 malicious or safe?
103.46.218.21 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 103.46.218.21?
The reverse DNS (PTR) record for 103.46.218.21 is 03-web-shared.tnf.pf. This hostname is forward-confirmed, meaning it resolves back to the same address.
What ports are open on 103.46.218.21?
Responsive ports observed on 103.46.218.21 include 80, 443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.
Is 103.46.218.21 a VPN, proxy, or data center address?
103.46.218.21 is classified as a residential network based on network ownership and behavioural analysis.