# IP INTELLIGENCE BRIEFING: 103.99.38.222/32
Date: 2026-07-30
Analyst: IPDebrief Intelligence Division
Classification: Standard Threat Intelligence
---
## EXECUTIVE SUMMARY
Target IP 103.99.38.222 is classified as LOW RISK with a risk score of 0/100. The address belongs to a commercial web hosting infrastructure operated by MOORTHY BADDI (ASN 151734) in Noida, Uttar Pradesh, India. No active threat indicators or malicious activity were observed.
---
## OWNERSHIP AND GEOLOCATION
| Attribute | Value |
|---|---|
| ASN | 151734 |
| Organization | MOORTHY BADDI |
| Netname | YOTTA |
| CIDR Block | 103.99.36.0/22 |
| Country | India (IN) |
| Region | Uttar Pradesh |
| City | Noida |
| RIR | APNIC |
| Geo Plausibility | Valid |
Geolocation validation confirms the IP's claimed location with 5 probe samples, showing consistent RTT measurements (243-250ms) and distance verification (6,251.5km from probe origin).
---
## NETWORK INFRASTRUCTURE
Service Role: Web Server
Open Ports:
- Port 80/TCP (HTTP)
- Port 443/TCP (HTTPS)
- Port 22/TCP (SSH - OpenSSH_9.6p1 Ubuntu-3ubuntu13.18)
Reverse Proxy Detection: TLS certificate analysis confirms CloudFlare Origin SSL infrastructure, indicating this IP may be a backend origin server protected by CloudFlare's CDN/waf services.
Server Fingerprint: nginx/1.31.3
---
## THREAT ASSESSMENT
Current Risk Profile:
- Risk Score: 0
- Abuse Confidence Score: N/A
- Blacklist Count: 0
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Threat Indicators: No threat indicators detected across all scanned threat feeds.
---
## DNS AND EMAIL AUTHENTICATION
| Check | Result |
|---|---|
| Forward Resolution | Not Confirmed |
| PTR Hostnames | None |
| Hosted Domains | aaptor.com, *.aaptor.com |
| SPF Record | Absent |
| DMARC Record | Absent |
| DNSSEC Valid | Yes |
Assessment: The absence of SPF and DMARC records suggests this is a backend infrastructure IP rather than a public-facing email server. DNSSEC validation confirms proper DNS security configuration.
---
## NEIGHBORHOOD ANALYSIS
Subnet: 103.99.38.0/24
Total Siblings: 10
Abuse Density: 0%
Risk Distribution in Subnet:
- High Risk: 0
- Medium Risk: 1 (103.99.38.236, Risk Score: 40)
- Low Risk: 9
Notable Neighbors:
- 103.99.38.236 (Risk Score: 40) - Elevated risk within subnet
- 103.99.38.128, 103.99.38.131, 103.99.38.142, 103.99.38.145, 103.99.38.154, 103.99.38.212, 103.99.38.235 (Risk Score: 25)
- 103.99.38.105, 103.99.38.156 (Risk Score: 0)
Assessment: The target IP shows no elevated risk relative to its subnet. One neighbor (103.99.38.236) demonstrates higher risk activity.
---
## OBSERVATION HISTORY
Total Observations: 15 signals
Recent Activity: No ownership changes, no threat persistence detected
Key Observations (Last 24 Hours):
- 2026-07-30 14:02: Ownership signal (Confidence: 85%)
- 2026-07-30 14:01: Geolocation probe (Confidence: 90%)
- 2026-07-30 14:00: HTTP fingerprint (Confidence: 80%) - Status 200, nginx/1.31.3
- 2026-07-30 13:58: Network classification (Confidence: 30%)
- 2026-07-30 13:58: Geolocation inference (Confidence: 52%)
Temporal Analysis:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Persistently Malicious: No
---
## CONTROL PLANE ANALYSIS
| Metric | Value |
|---|---|
| Route Stability | Unstable |
| DNSBL Listed Count | 0 |
| DNSBL Total Lists | 8 |
| Operator Score | 0.1304 (Minimal) |
| RPKI State | N/A |
| Route Changes (30d) | 0 |
---
## SECURITY RECOMMENDATIONS
Action Required: None
Recommendations: Empty (no immediate action required)
The target IP presents no actionable threats. Standard monitoring procedures are sufficient. No firewall rules or blocking actions are recommended based on current intelligence.
---
## RELATIONSHIP GRAPH
Connected Entities: 4 relationships identified
- All relationships classified as "Same Network" pointing to network entity "YOTTA"
- No relationships to hostnames, organizations, or certificates outside the network
---
## CONCLUSION
IP 103.99.38.222 is a low-risk commercial web server infrastructure component. The absence of threat indicators, combined with CloudFlare origin certificate evidence, suggests
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | MOORTHY BADDI |
| ASN | AS151734 |
| Network Name | YOTTA |
| CIDR Block | 103.99.36.0/22 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.31.3 |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
๐ TLS Certificate
| SANs | *.aaptor.comaaptor.com |
| Valid From | 2026-07-30T05:07:00+00:00 |
| Valid Until | 2041-07-26T05:07:00+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 5475 days |
| Serial Number | 42BF6B9FA69B959747F0059FE683CF25ABC917DC |
| Thumbprint | CA67E761A05816BD305E276F511662CAE50A53E1 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 21:53:39 UTC |
| Last Seen | 2026-07-30 13:55:25 UTC |
| Profile Built | 2026-07-30 14:06:50 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.