# IP INTELLIGENCE BRIEFING
Target IP: 103.66.198.234/32
Date: 2026-07-30
Classification: LOW RISK / LEGITIMATE INFRASTRUCTURE
---
## EXECUTIVE SUMMARY
IP 103.66.198.234 is classified as LOW RISK with a risk score of 0. The address operates as a standard web server within Indonesia's CEPATNET-ID network infrastructure (Moratelindo Hostmaster). No threat indicators, blacklist entries, or malicious activity were detected. Recommended action: Monitor but no blocking required.
---
## PROFILE DATA
Ownership & Registration:
- ASN: 131111
- Organization: Moratelindo Hostmaster
- Network Block: 103.66.196.0/22
- RIR: APNIC
- Abuse Contact: abuse@moratelindo.co.id
Geolocation:
- Country: Indonesia (ID)
- Region: Jakarta Pusat (Jl. Panataran No. 9)
- Postal Code: 10320
Network Role:
- Service: Web Server
- Classification: Not cloud, CDN, VPN, proxy, or residential
DNS Resolution:
- PTR Record: kinderfieldhighfieldbgr.my.id
- Forward Resolution: Confirmed
- Forward Hostname: kinderfieldhighfieldbgr.my.id
- Email Auth: SPF and DMARC configured
---
## SERVICES & NETWORK SIGNATURE
Open Ports:
- TCP/80 - HTTP
- TCP/443 - HTTPS
TLS Certificate:
- Issuer: Let's Encrypt (YR2)
- Subject: CN=acs.sti-app.my.id
- Protocol: TLS 1.3
- Cipher Suite: TLS_AES_256_GCM_SHA384
- Server Banner: nginx
---
## THREAT INDICATORS
Current Status: CLEAN
- Abuse Confidence Score: None
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Threat Feeds: None
- Known Campaigns: None
---
## OBSERVATION HISTORY
Total Observations: 17 signals recorded
Recent Activity (2026-07-30):
- 16:04:10 UTC - Subnet classification: Clean, abuse density 0, 1 active sibling
- 16:03:34 UTC - BGP routing confirmed for prefix 103.66.198.0/24, ASN 131111, 2 communities
- 16:02:40 UTC - Service scan: nginx server, TLS 1.3 enabled, ports 80/443 open
- 16:01:07 UTC - Ownership confirmed: Moratelindo Hostmaster, Jakarta Pusat, Indonesia
Temporal Analysis:
- Ownership Changes: 0
- Threat Persistence: 0 days
- Threat Observation Count: 0
- Persistently Malicious: No
---
## RELATIONSHIP GRAPH
DNS Associations:
- kinderfieldhighfieldbgr.my.id (multiple entries)
Network Associations:
- CEPATNET-ID network block
Correlated Entities: 0
---
## NEIGHBORHOOD ANALYSIS
Subnet: 103.66.198.234/24
- Abuse Density: 0
- Total Siblings: 0
- Active Siblings: 0
- Threat Siblings: 0
- Risk Distribution: No high/medium/low risk neighbors detected
---
## SECURITY ACTIONS
Recommended Actions: None
- Risk Score: 0
- Firewall Rules: Not required
- WAF Rules: Not required
Justification: Low risk profile with no threat indicators. IP operates as legitimate web hosting infrastructure with valid TLS certificates and proper email authentication configured.
---
## INTELLIGENCE ASSESSMENT
IP 103.66.198.234 represents standard Indonesian web hosting infrastructure operated by Moratelindo Hostmaster. The address exhibits characteristics of legitimate infrastructure:
- Valid BGP routing and ASN registration
- Proper DNS and email authentication (SPF/DMARC)
- Standard web server services with modern TLS 1.3
- No association with known threat actors or campaigns
- Clean neighborhood profile with no abusive neighbors
Threat Level: NONE
Recommended Handling: Monitor passively; no blocking or mitigation actions required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Moratelindo Hostmaster |
| ASN | AS131111 |
| Network Name | CEPATNET-ID |
| CIDR Block | 103.66.196.0/22 |
| RIR | APNIC |
| Country | ID |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | kinderfieldhighfieldbgr.my.id |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | kinderfieldhighfieldbgr.my.id |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | nginx |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | acs.sti-app.my.id |
| Valid From | 2026-06-10T16:23:46+00:00 |
| Valid Until | 2026-09-08T16:23:45+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 056D83F17AB4420273C68F73CECC2E42D5DE |
| Thumbprint | 4332405FB881CF8D0D1451F2A4C0E3FAD33C25A6 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-28 10:05:55 UTC |
| Last Seen | 2026-08-13 00:38:47 UTC |
| Profile Built | 2026-08-11 05:44:37 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 25 |
Full dossier details are available via our API.