# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 111.68.99.9/32
Date: 2026-07-27
Classification: Moderate Risk Assessment
---
## EXECUTIVE SUMMARY
IP 111.68.99.9 presents a moderate risk profile (Score: 40) with no active threat indicators. The address is associated with Bahria University infrastructure in Lahore, Pakistan, running ASP.NET web services. No malicious behavior observed; however, the IP appears on 2 of 8 DNSBLs. Recommend monitoring but not immediate blocking.
---
## NETWORK OWNERSHIP & GEOLOCATION
- ASN: 45773 (PERN-PK)
- Organization: Abdullah Fayaz Chattha
- RIR: APNIC
- CIDR Block: 111.68.99.8/29
- Country: Pakistan (PK)
- Region: Punjab
- City: Lahore
- Coordinates: 31.58°N, 74.33°E
---
## SERVICE PROFILE & DNS
- DNS PTR: 111.68.99.9.bahria.edu.pk
- Forward Resolution: Confirmed to bahria.edu.pk
- Open Ports:
- TCP/80 (HTTP)
- TCP/8443 (HTTPS-alt)
- Server Technology: Kestrel (ASP.NET)
- HTTP Version: 1.1
- Status Code: 302 (Redirect)
- Header: X-Powered-By: ASP.NET
---
## THREAT INDICATORS
- Risk Score: 40/100 (Moderate)
- Blacklist Count: 2/8 DNSBLs listed
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Active Campaigns: None detected
- Abuse Confidence: Not applicable
---
## NEIGHBORHOOD ANALYSIS
- Subnet: 111.68.99.0/24
- Abuse Density: 0%
- Classification: Clean
- Threat Siblings: 0
- Total Siblings: 1 (in /29 block)
---
## RELATIONSHIP GRAPH
- Network Associations: PERN-PK (4 relationships)
- DNS Associations: 111.68.99.9.bahria.edu.pk (4 relationships)
- No additional entity correlations detected
---
## OBSERVATION HISTORY (18 Signals)
Recent activity indicates stable infrastructure:
- Geolocation signals consistent (Lahore, Pakistan)
- HTTP fingerprinting shows ASP.NET Kestrel server
- Network service scanning confirms ports 80/8443
- No escalation in risk signals over observation period
- Risk Persistence: False (not persistently malicious)
---
## SECURITY ACTIONS & RECOMMENDATIONS
Firewall Rules
```bash
# iptables
iptables -A INPUT -s 111.68.99.9 -j DROP
# nftables
nft add rule inet filter input ip saddr 111.68.99.9 drop
# Cloudflare WAF
{"description":"Block 111.68.99.9 — IPDebrief risk score 40","action":"block","filter":{"expression":"ip.src eq 111.68.99.9"}}
```
Analyst Notes
- Do not block immediately: Risk score 40 indicates moderate concern without active threat indicators
- Monitor DNSBL status: 2 of 8 blacklist listings require investigation
- Verify Bahria University association: Confirm legitimate institutional use
- Recommended action: Add to monitoring watchlist with 14-day review cycle
- False positive potential: Educational institution IP with legitimate web services
---
## CONCLUSION
IP 111.68.99.9 exhibits characteristics of legitimate web hosting infrastructure with moderate risk due to DNSBL listings. No evidence of malicious activity, command-and-control, or attack tooling. Treat as low-priority monitoring target unless additional threat indicators emerge.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Abdullah Fayaz Chattha |
| ASN | AS45773 |
| Network Name | PERN-PK |
| CIDR Block | 111.68.99.8/29 |
| RIR | APNIC |
| Country | PK |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 111.68.99.9.bahria.edu.pk |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 111.68.99.9.bahria.edu.pk |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Multi-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 8443 | https-alt | tcp | — |
| Closed Ports | 22, 25, 443, 3389, 8080 (2 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS45773 |
| Network Prefix | 111.68.99.0/24 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 17% | 2 | 3 |
| ownership | 17% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 12% | 2 | 2 |
| Overall | 18% | 10 | 17 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-14 09:42:34 UTC |
| Last Seen | 2026-09-18 00:59:48 UTC |
| Profile Built | 2026-08-31 08:12:44 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 29 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 111.68.99.9
Who owns the IP address 111.68.99.9?
111.68.99.9 is registered to Abdullah Fayaz Chattha. The address falls within the 111.68.99.8/29 network block. Registration is held at APNIC.
Where is 111.68.99.9 located?
Geolocation data places 111.68.99.9 in London, Punjab, United Kingdom. The local time zone is Europe/London. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 111.68.99.9 malicious or safe?
111.68.99.9 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 111.68.99.9?
The reverse DNS (PTR) record for 111.68.99.9 is 111.68.99.9.bahria.edu.pk. This hostname is not forward-confirmed, so it should be treated as a weak signal.
What ports are open on 111.68.99.9?
Responsive ports observed on 111.68.99.9 include 80, 8443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.