IP INTELLIGENCE BRIEFING: 103.97.208.10
Classification: MODERATE RISK
Date of Analysis: 2026-07-30
Analysis Tool: IPDebrief Intelligence Platform
---
EXECUTIVE SUMMARY
IP address 103.97.208.10 is associated with IDC Legend Corp administrator (ASN 10010) in Japan. The IP presents moderate risk (score: 40) with no active threat indicators but exhibits two DNSBL listings across eight total lists. The subnet demonstrates clean classification with zero abuse density. SOC teams may consider blocking based on organizational policy thresholds.
---
OWNERSHIP AND GEOLOCATION
- Organization: IDC Legend Corp administrator
- Network Name: IDCLEGEND-JP
- CIDR Block: 103.97.208.0/23
- ASN: 10010 (APNIC RIR)
- Country: Japan (JP)
- Geolocation Accuracy: 600km radius, consensus validated
---
THREAT ASSESSMENT
Current Risk Profile:
- Overall Risk Score: 40 (Moderate)
- Threat Indicators: None detected
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0 direct listings
Control Plane Indicators:
- Route Stability: Unstable (isRouteStable: false)
- DNSBL Listings: 2 of 8 total lists
- Operator Score: 0.1304 (Minimal)
- DNSSEC: Valid
---
NETWORK BEHAVIOR
Service Exposure:
- Open Ports: None detected
- Service Purpose: Firewalled / No Services
- TLS Certificates: None
- HTTP Banner: None
Network Role Classification:
- Not identified as CDN, cloud, VPN, proxy, Tor, hosting, mobile, residential, or anycast
Historical Observations (15 total):
- Recent subnet classification: Clean
- Abuse density: 0
- Ownership changes: 0
- Threat observation count: 0
- Threat persistence: Not observed
- Port scanning activity detected but no services resolved
---
NEIGHBORHOOD ANALYSIS
Subnet: 103.97.208.0/24
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 0
- Abuse Density: 0
- Classification: Clean
No neighboring IPs in the /24 demonstrate malicious activity.
---
RELATIONSHIP GRAPH
All identified relationships point to the IDCLEGEND-JP network. No external hostnames, organizations, or certificates were associated with this IP.
---
RECOMMENDED ACTIONS
Firewall Rule Implementation:
- iptables: `iptables -A INPUT -s 103.97.208.10 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 103.97.208.10 drop`
- nginx: `deny 103.97.208.10;`
- pfSense: Block 103.97.208.10/32
- Cloudflare WAF: Block with expression `ip.src eq 103.97.208.10`
- AWS WAF: Add 103.97.208.10/32 to IP set
Rationale: The IP presents moderate risk with DNSBL listings. While no active threat indicators were observed, the unstable routing status and moderate risk score warrant defensive blocking.
---
MONITORING RECOMMENDATIONS
- Monitor for any emergence of open ports or service banners
- Watch for new threat indicators or blacklist additions
- Track subnet-level activity across 103.97.208.0/24
- Verify route stability improvements over time
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IDC Legend Corp administrator |
| ASN | AS10010 |
| Network Name | IDCLEGEND-JP |
| CIDR Block | 103.97.208.0/23 |
| RIR | APNIC |
| Country | JP |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 21:53:39 UTC |
| Last Seen | 2026-07-30 13:55:15 UTC |
| Profile Built | 2026-07-30 14:06:50 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.