# IP Intelligence Briefing: 103.49.238.22/32
## Executive Summary
Target IP 103.49.238.22 presents a moderate risk profile (risk score: 50) associated with Indonesian cloud hosting infrastructure. The subnet demonstrates minimal threat activity with an abuse density of 0. No active campaigns or known attacker indicators were identified. The IP appears to be firewalled with no open services, though control plane data indicates some DNSBL presence.
## Profile Overview
Risk Classification: Moderate Risk (50)
Ownership: ASN 136052 / IRT-IDCLOUDHOST-ID / PT Cloud Hosting Indonesia
Geolocation: Sukabumi, Jawa, Indonesia (APNIC RIR)
Network Classification: Infrastructure / Firewalled
Stability: Not persistently malicious
## Threat Indicators
- Abuse Confidence: None (null)
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- Known Campaigns: None identified
- Threat Feeds: No active indicators
Control Plane Concerns:
- DNSBL Listed: 2 of 8 total lists
- Route Stability: False (instability detected)
- BGP Prefix: 103.49.238.0/24
## Network Services
- Open Ports: None detected
- TLS Certificate: None
- HTTP Banner: None
- Service Purpose: Firewalled / No Services
## DNS Intelligence
- PTR Hostname: ip103-49-238-22.cloudhost.web.id
- Domain: web.id
- Forward Resolution: Confirmed (1 record)
- Email Authentication: SPF/DMARC not configured
- Hosted Domains: 0
## Neighborhood Analysis (103.49.238.0/24)
Subnet Risk Assessment: Clean
Abuse Density: 0
Total Siblings: 6 active
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 103.49.238.23 | 50 | 50 |
| 103.49.238.35 | 25 | 50 |
| 103.49.238.63 | 50 | 50 |
| 103.49.238.64 | 50 | 50 |
| 103.49.238.104 | 50 | 50 |
| 103.49.238.212 | 25 | 50 |
Risk distribution: 4 medium-risk, 2 low-risk IPs in the subnet.
## Observation History
17 total observations recorded. Key signals include:
- ASN resolution consistent across observations (AS136052)
- Geolocation signals show multi-signal inference with 52% confidence
- Alienvault OTX signals detected with 50 pulses
- Operator score: 0.1304 (Minimal)
- No ownership changes detected
## Relationship Graph
Primary Associations:
- 28 relationships identified
- Same Network: IDNIC-IDCLOUDHOST-ID (multiple instances)
- DNS Association: ip103-49-238-22.cloudhost.web.id (repeated associations)
## Recommended Actions
No immediate blocking recommended. The IP demonstrates:
- Moderate risk score with no active threat indicators
- Clean neighborhood reputation
- No services exposed
- Legitimate cloud hosting infrastructure profile
Monitoring Recommendations:
1. Monitor DNSBL listing changes
2. Track route stability (currently unstable)
3. Review for any new threat indicator emergence
Firewall Classification: Allow with monitoring (risk score 50, moderate threat)
---
*Report generated based on IPDebrief intelligence platform data. All findings derived from observed signals and validated through multiple data sources.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-IDCLOUDHOST-ID |
| ASN | AS136052 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ip103-49-238-22.cloudhost.web.id |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | ip103-49-238-22.cloudhost.web.id |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 22% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-09 11:33:24 UTC |
| Last Seen | 2026-06-25 14:37:19 UTC |
| Profile Built | 2026-06-25 14:57:06 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 24 |
Full dossier details are available via our API.