# IP Intelligence Briefing: 116.58.43.34/32
Classification: Low Risk (Risk Score: 15)
Date of Analysis: 2026-07-28
## Overview
The target IP address 116.58.43.34 operates within ASN 17563 (IRT-NEXLINX-PK) and is associated with the NEXLINX-AP network block (116.58.0.0/17). The IP resolves to the hostname exchange.wasalhr.pk, indicating enterprise email infrastructure deployment.
## Technical Profile
- Organization: IRT-NEXLINX-PK
- Network: 116.58.43.0/24 (BGP Prefix)
- Service Purpose: Web Server (HTTPS/443)
- Geolocation: Pakistan (Lahore, Punjab) – Certificate-based validation confirms PK jurisdiction
- DNS Configuration: SPF and DMARC records present; forward resolution to exchange.wasalhr.pk confirmed
## Threat Indicators
No active threat indicators detected. The IP is not flagged as a known attacker, Tor exit node, or spam source. Blacklist enumeration shows 0 explicit listings. However, the control plane indicates 1 DNSBL listing across 8 total lists, warranting monitoring.
## Network Environment
The /24 neighborhood (116.58.43.0/24) contains 1 active sibling IP: 116.58.43.35 (Risk Score: 40, Authority Score: 60). The subnet abuse density is minimal (0.0), indicating isolated activity rather than coordinated abuse infrastructure.
## Historical Signals
Observation history reveals 18 signals collected. Recent geolocation data consistently identifies the IP as Pakistani infrastructure (Lahore, Gulberg III). The IP has maintained ownership stability with no ownership changes recorded. TLS certificate analysis shows issuance by Sophos CA with organizational attribution to WASA (Lahore, Punjab, PK).
## Infrastructure Characteristics
- HTTP Status: 302 (Redirect)
- Security Headers: HSTS enabled; CSP absent
- Protocol: HTTP/1.1
- Response Time: 1,347ms
- Certificate: Self-signed: False; Valid certificate chain present
## Security Assessment
The IP represents legitimate enterprise email infrastructure. The hostname exchange.wasalhr.pk and organization WASA indicate business operations rather than malicious activity. No evidence of command-and-control, scanning, or exploitation activity. The neighbor 116.58.43.35 presents elevated risk and should be monitored.
## Recommended Actions
No immediate firewall rules recommended. The low risk score (15) and absence of threat indicators support continued traffic monitoring. The single DNSBL listing is informational and does not indicate active abuse. Monitor the sibling IP 116.58.43.35 for any escalation in risk profile.
Status: PASSIVE MONITORING
Confidence: HIGH
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-NEXLINX-PK |
| ASN | AS17563 |
| Network Name | NEXLINX-AP |
| CIDR Block | 116.58.0.0/17 |
| RIR | APNIC |
| Country | PK |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | exchange.wasalhr.pk |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | exchange.wasalhr.pk |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | — |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | 2015-08-01T00:00:00+00:00 |
| Valid Until | 2036-12-31T23:59:59+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 7823 days |
🛡️ Public Network Snapshot
| Origin ASN | AS17563 |
| Network Prefix | 116.58.43.0/24 |
| Route mapping | Found |
| HSTS | Enabled |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 21% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 17% | 2 | 3 |
| ownership | 17% | 2 | 3 |
| reputation | 8% | 1 | 2 |
| geolocation | 13% | 1 | 1 |
| Overall | 14% | 9 | 14 |
| Data Coherence | Mixed Signals (68%) — 2 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
⚠ TLS certificate claims PK but primary geo says GB
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-16 10:35:50 UTC |
| Last Seen | 2026-09-02 14:45:45 UTC |
| Profile Built | 2026-09-02 15:01:08 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 32 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 116.58.43.34
Who owns the IP address 116.58.43.34?
116.58.43.34 is registered to IRT-NEXLINX-PK. The address falls within the 116.58.0.0/17 network block. Registration is held at APNIC.
Where is 116.58.43.34 located?
Geolocation data places 116.58.43.34 in London, Punjab, United Kingdom. The local time zone is Europe/London. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 116.58.43.34 malicious or safe?
116.58.43.34 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 116.58.43.34?
The reverse DNS (PTR) record for 116.58.43.34 is exchange.wasalhr.pk. This hostname is not forward-confirmed, so it should be treated as a weak signal.
What ports are open on 116.58.43.34?
Responsive ports observed on 116.58.43.34 include 443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.