# INTELLIGENCE BRIEFING: IP 103.79.17.139/32
Classification: MODERATE RISK | Date: Current Intelligence Cycle
Prepared For: SOC Operations Team | Status: REQUIRES MONITORING
---
## EXECUTIVE SUMMARY
Target IP 103.79.17.139 is a web server infrastructure endpoint operated by IRT-SHARPCOM-PK (ASN 138453) within the SHARPCOM-PK network (103.79.16.0/22). The IP exhibits a risk score of 50/100, classified as Moderate Risk, with no active threat indicators but notable presence in DNSBL listings. Infrastructure is hosted in Pakistan with Microsoft IIS/10.0 serving web traffic.
---
## OWNERSHIP & GEOLOCATION
| Attribute | Value |
|---|---|
| Organization | IRT-SHARPCOM-PK |
| ASN | 138453 |
| Network | 103.79.16.0/22 |
| Country | Pakistan (PK) |
| RIR | APNIC |
| BGP Prefix | 103.79.17.0/24 |
| Service Role | Web Server |
---
## INFRASTRUCTURE PROFILE
Network Services:
- Open Ports: TCP/80 (HTTP), TCP/443 (HTTPS)
- Server: Microsoft-IIS/10.0
- HTTP Version: 2.0
- TTFB: 844ms
SSL/TLS Certificate:
- Issuer: CN=Certera RSA DV SSL CA 2, O=Certera LLC, C=US
- Subject: CN=oms2.leopardsoms.pk
- SANs: oms2.leopardsoms.pk, www.oms2.leopardsoms.pk
- Certificate Type: Not self-signed
Security Headers:
- HSTS: Enabled (max-age=2592000)
- HTTP/2: Supported
- X-Frame-Options: DENY
- CSP: Not configured
- Referrer Policy: Not configured
---
## THREAT ASSESSMENT
Risk Indicators:
- Risk Score: 50 (Moderate)
- Abuse Confidence: Not applicable
- Blacklist Status: Listed on 2 of 8 DNSBL lists
- Campaign Affiliation: None identified
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
Control Plane Status:
- Route Stability: False
- DNSSEC: Valid
- Operator Score: 0.1304 (Minimal)
- RPKI State: Not determined
---
## OBSERVATION HISTORY
Total Signals Observed: 13
Latest Observation: 2026-07-31
Temporal Analysis:
- Threat Persistence Days: 0
- Is Persistently Malicious: No
- Ownership Changes: 0
- Average Ownership Days: Not determined
Signal Types Monitored:
- HTTP Response Characteristics
- Network Classification
- TLS Certificate Validity
- Geolocation Data
- Port Scanning Activity
---
## NEIGHBORHOOD ANALYSIS
Subnet: 103.79.17.0/24
Abuse Density: 0.0
Total Siblings: 2
| Neighbor IP | Risk Score | Authority Score |
|---|---|---|
| 103.79.17.129 | 25 | 50 |
| 103.79.17.134 | 15 | 50 |
Assessment: Subnet exhibits low abuse density with no high-risk neighbors. Target IP is an outlier within its immediate subnet.
---
## RELATIONSHIP MAPPING
Identified Relationships: 5
Primary Association: SHARPCOM-PK Network (Multiple same-network references)
All relationships map to the same network entity, indicating consistent infrastructure hosting.
---
## RECOMMENDED ACTIONS
Current Risk-Based Recommendations:
| System | Recommended Action |
|---|---|
| iptables | `iptables -A INPUT -s 103.79.17.139 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 103.79.17.139 drop` |
| nginx | `deny 103.79.17.139;` |
| pfSense | `103.79.17.139/32` |
| Cloudflare WAF | Block (Risk Score 50) |
| AWS WAF | Block (103.79.17.139/32) |
Operational Guidance: These recommendations are probabilistic. Combine with additional threat signals before implementing blocking measures. Monitor for legitimate business traffic from this IP range.
---
## INTELLIGENCE CONCLUSION
IP 103.79.17.139 presents moderate risk due to DNSBL presence but lacks active threat indicators. The infrastructure appears to be a legitimate web hosting endpoint for oms2.leopardsoms.pk. Recommend monitoring rather than immediate blocking unless additional threat intelligence emerges. Subnet context shows no correlated malicious activity from neighboring IPs.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-SHARPCOM-PK |
| ASN | AS138453 |
| Network Name | SHARPCOM-PK |
| CIDR Block | 103.79.16.0/22 |
| RIR | APNIC |
| Country | PK |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Microsoft-IIS/10.0 |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | oms2.leopardsoms.pkwww.oms2.leopardsoms.pk |
| Valid From | 2026-04-14T00:00:00+00:00 |
| Valid Until | 2026-10-29T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 198 days |
| Serial Number | 52408AC10526C5EBD71DD51EC3218174 |
| Thumbprint | 5CD7BC54B836D8505A31E98BEB9B5B5035134BA5 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 11:02:50 UTC |
| Last Seen | 2026-08-05 06:11:20 UTC |
| Profile Built | 2026-07-31 01:41:50 UTC |
| Data Freshness | Live |
| Signal Types | 14 |
| Total Observations | 14 |
Full dossier details are available via our API.