# IP Threat Intelligence Briefing: 103.60.175.64
Classification: Moderate Risk (55/100)
Date of Analysis: Current
Intelligence Source: IPDebrief Intelligence Platform
## Executive Summary
IP address 103.60.175.64 is a Bangladesh-based IP from Mazedanetworks.net with a moderate risk score of 55/100. The IP shows network instability and is listed on 3 out of 8 DNSBLs. While no active threat indicators were detected, the elevated risk score warrants monitoring and defensive firewall rules.
## Geographic and Network Attribution
- Country: Bangladesh (BD) – Dhaka Division
- ASN: 63996
- BGP Prefix: 103.60.175.0/24
- Organization: IRT-MNL-BD (Mazedanetworks)
- DNS Domain: mazedanetworks.net
- PTR Record: 103.60.175-64.mazedanetworks.net
The BGP route is marked as unstable, indicating potential routing anomalies or recent network changes.
## Threat Profile
- Risk Score: 55/100 (Moderate Risk)
- Abuse Confidence: Not applicable
- Blacklist Status: Listed on 3 DNSBLs
- Known Threat Indicators: None detected
- Tor/Proxy/VPN: Negative
- Campaign Association: No known campaigns correlated
The IP shows no active malicious indicators but maintains an elevated risk posture due to DNSBL listings and operator scoring of 0.1304 (Minimal).
## Neighborhood Analysis
Subnet 103.60.175.0/24 shows:
- Abuse Density: 0
- Active Neighbors: 2
- Risk Distribution: 1 medium-risk neighbor (103.60.175.34, score 55), 1 unassessed (103.60.175.100)
The subnet demonstrates low abuse density with one peer IP sharing the same moderate risk score.
## Historical Signals
Twelve observations recorded with signals from APNIC (IRT-MNL-BD), MaxMind geolocation (Dhaka), and control plane data. Recent signals indicate consistent network registration under IRT-MNL-BD with abuse contact abuse@mazedanetworks.net.
## Recommended Actions
Monitoring: Increase logging verbosity and review recent activity from this IP source.
Firewall Rules (Deploy as needed):
- iptables: `iptables -A INPUT -s 103.60.175.64 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 103.60.175.64 drop`
- nginx: `deny 103.60.175.64;`
- pfSense: Block 103.60.175.64/32
- Cloudflare WAF: Block via expression `ip.src eq 103.60.175.64`
- AWS WAF: Add 103.60.175.64/32 to block set
## SOC Analyst Guidance
This IP presents a moderate risk requiring defensive monitoring. The moderate score combined with DNSBL listings suggests either legitimate high-traffic activity or sporadic abuse. Implement firewall blocking if this IP initiates connection attempts to your infrastructure, and monitor for any behavioral anomalies. The associated subnet shows similar risk profiles, warranting consideration of subnet-level blocking if risk thresholds require it.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-MNL-BD |
| ASN | AS63996 |
| Network Name | MNL-BD |
| CIDR Block | 103.60.175.0/24 |
| RIR | APNIC |
| Country | BD |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 103.60.175-64.mazedanetworks.net |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 103.60.175-64.mazedanetworks.net |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS63996 |
| Network Prefix | 103.60.175.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-07 06:26:45 UTC |
| Last Seen | 2026-08-29 06:16:27 UTC |
| Profile Built | 2026-08-29 06:16:48 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 103.60.175.64
Who owns the IP address 103.60.175.64?
103.60.175.64 is registered to IRT-MNL-BD. The address falls within the 103.60.175.0/24 network block. Registration is held at APNIC.
Where is 103.60.175.64 located?
Geolocation data places 103.60.175.64 in Hong Kong, Dhaka Division, Hong Kong. The local time zone is Asia/Hong_Kong. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 103.60.175.64 malicious or safe?
103.60.175.64 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 103.60.175.64?
The reverse DNS (PTR) record for 103.60.175.64 is 103.60.175-64.mazedanetworks.net. This hostname is not forward-confirmed, so it should be treated as a weak signal.