IPDebrief

116.58.43.34

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 116.58.43.34/32

Classification: Low Risk (Risk Score: 15)

Date of Analysis: 2026-07-28

## Overview

The target IP address 116.58.43.34 operates within ASN 17563 (IRT-NEXLINX-PK) and is associated with the NEXLINX-AP network block (116.58.0.0/17). The IP resolves to the hostname exchange.wasalhr.pk, indicating enterprise email infrastructure deployment.

## Technical Profile

## Threat Indicators

No active threat indicators detected. The IP is not flagged as a known attacker, Tor exit node, or spam source. Blacklist enumeration shows 0 explicit listings. However, the control plane indicates 1 DNSBL listing across 8 total lists, warranting monitoring.

## Network Environment

The /24 neighborhood (116.58.43.0/24) contains 1 active sibling IP: 116.58.43.35 (Risk Score: 40, Authority Score: 60). The subnet abuse density is minimal (0.0), indicating isolated activity rather than coordinated abuse infrastructure.

## Historical Signals

Observation history reveals 18 signals collected. Recent geolocation data consistently identifies the IP as Pakistani infrastructure (Lahore, Gulberg III). The IP has maintained ownership stability with no ownership changes recorded. TLS certificate analysis shows issuance by Sophos CA with organizational attribution to WASA (Lahore, Punjab, PK).

## Infrastructure Characteristics

## Security Assessment

The IP represents legitimate enterprise email infrastructure. The hostname exchange.wasalhr.pk and organization WASA indicate business operations rather than malicious activity. No evidence of command-and-control, scanning, or exploitation activity. The neighbor 116.58.43.35 presents elevated risk and should be monitored.

## Recommended Actions

No immediate firewall rules recommended. The low risk score (15) and absence of threat indicators support continued traffic monitoring. The single DNSBL listing is informational and does not indicate active abuse. Monitor the sibling IP 116.58.43.35 for any escalation in risk profile.

Status: PASSIVE MONITORING

Confidence: HIGH

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇬🇧 United Kingdom
RegionPunjab
CityLondon
TimezoneEurope/London
Latitude31.56
Longitude74.36

🏢 Ownership & Registration

OrganizationIRT-NEXLINX-PK
ASNAS17563
Network NameNEXLINX-AP
CIDR Block116.58.0.0/17
RIRAPNIC
CountryPK
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRexchange.wasalhr.pk
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesexchange.wasalhr.pk

🔐 DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCPresent
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
443httpstcp—
Closed Ports22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned)
ServerWeb server detected
HTTP Title—

🔐 TLS Certificate

🔒
E=ranaje508@gmail.com, CN=SophosApplianceCertificate_C230768VY6HFQ7F, OU=OU, O=WASA, L=lAHORE, S=Punjab, C=PK
Issued by E=ranaje508@gmail.com, CN=Sophos_CA_C230768VY6HFQ7F, OU=OU, O=WASA, L=lAHORE, S=Punjab, C=PK
Self-signed: No
SANsNone
Valid From2015-08-01T00:00:00+00:00
Valid Until2036-12-31T23:59:59+00:00
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period7823 days

🛡️ Public Network Snapshot

Origin ASNAS17563
Network Prefix116.58.43.0/24
Route mappingFound
HSTSEnabled
CSPNot detected
HTTP/2Not detected

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
21%
24
routing
8%
11
services
17%
23
ownership
17%
23
reputation
8%
12
geolocation
13%
11
Overall14%914
Coverage: 3/6 dimensions · Data sufficiency: partial
Data CoherenceMixed Signals (68%) — 2 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: PK, GB
⚠ TLS certificate claims PK but primary geo says GB

📅 Observation Timeline 🔄 Live

First Seen2026-07-16 10:35:50 UTC
Last Seen2026-09-02 14:45:45 UTC
Profile Built2026-09-02 15:01:08 UTC
Data FreshnessLive
Signal Types24
Total Observations32
🔍 24 signal types · 32 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 116.58.43.34

Who owns the IP address 116.58.43.34?

116.58.43.34 is registered to IRT-NEXLINX-PK. The address falls within the 116.58.0.0/17 network block. Registration is held at APNIC.

Where is 116.58.43.34 located?

Geolocation data places 116.58.43.34 in London, Punjab, United Kingdom. The local time zone is Europe/London. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 116.58.43.34 malicious or safe?

116.58.43.34 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 116.58.43.34?

The reverse DNS (PTR) record for 116.58.43.34 is exchange.wasalhr.pk. This hostname is not forward-confirmed, so it should be treated as a weak signal.

What ports are open on 116.58.43.34?

Responsive ports observed on 116.58.43.34 include 443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.

🏘️ Related IP Addresses

Nearby addresses in 116.58.0.0/17

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.