# Intelligence Briefing: 163.61.38.135/32
Classification: Moderate Risk
Date: June 17, 2026
Analyst: IPDebrief Intelligence Platform
---
## Executive Summary
IP address 163.61.38.135 presents a moderate risk profile (Risk Score: 40/100) with no active threat indicators. The IP is associated with CHANDER PARKASH organization, registered under the JOYSVC network block within APNIC RIR. Geolocation analysis places the address in Noida, Uttar Pradesh, India. Despite the moderate risk classification, the IP shows no evidence of active malicious behavior, spam generation, or known campaign participation.
## Ownership and Geolocation
| Field | Value |
|---|---|
| **ASN** | 152565 |
| **Organization** | CHANDER PARKASH |
| **Network Name** | JOYSVC |
| **CIDR Block** | 163.61.38.0/24 |
| **Country** | India (IN) |
| **Region** | Uttar Pradesh |
| **City** | Noida |
| **RIR** | APNIC |
Geolocation confidence stands at 52% with an accuracy radius of 1,500 km. Multiple source signals confirmed geo-plausibility.
## Threat Assessment
Active Indicators
- Abuse Confidence Score: Not available
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Known Campaigns: None
Control Plane Analysis
- BGP Prefix: 163.61.38.0/23
- Route Stability: False
- DNSSEC Validation: Valid
- DNSBL Listings: 2 of 8 total lists
- Operator Score: 0.1304 (Minimal)
## Network Fingerprint
- HTTP Server: nginx/1.24.0
- HTTP Status: 200 OK
- HSTS Enabled: Yes
- HTTP/2 Support: No
- TLS Certificate: None observed
- TTFB: 1,205ms
- Services: No open ports detected (Firewalled / No Services)
## Neighborhood Analysis
Subnet: 163.61.38.0/24
Abuse Density: 0%
Classification: Clean
| Metric | Value |
|---|---|
| Total Siblings | 2 |
| Active Siblings | 1 |
| Threat Siblings | 0 |
| High Risk Neighbors | 0 |
| Medium Risk Neighbors | 0 |
| Low Risk Neighbors | 1 |
Notable Neighbor: 163.61.38.142 (Risk Score: 25)
## Relationship Graph
The IP demonstrates network-level relationships exclusively within the JOYSVC network block (163.61.38.0/24). No external organization, hostname, or certificate relationships were identified.
## Historical Observations
The IP has generated 20 observations over the monitoring period:
- Threat Persistence: 0 days
- Ownership Changes: 0
- Observation Count: 1
- Persistently Malicious: No
Recent signals indicate minimal activity with no escalation in risk profile.
## Recommended Actions
Given the moderate risk score (40) and lack of confirmed malicious indicators, the following firewall rules are recommended:
```bash
# iptables
iptables -A INPUT -s 163.61.38.135 -j DROP
# nftables
nft add rule inet filter input ip saddr 163.61.38.135 drop
# nginx
deny 163.61.38.135;
# pfSense
163.61.38.135/32
# Cloudflare WAF
{
"description": "Block 163.61.38.135 โ IPDebrief risk score 40",
"action": "block",
"filter": {
"expression": "ip.src eq 163.61.38.135"
}
}
# AWS WAF
{
"Addresses": ["163.61.38.135/32"],
"Description": "IPDebrief risk 40"
}
```
Note: These recommendations are probabilistic and should be combined with other signals before implementing blocking measures.
## Conclusion
IP 163.61.38.135 is classified as moderate risk but currently demonstrates no active threat behavior. The absence of open services, combined with clean neighborhood metrics and no blacklist presence, suggests this IP may be a legitimate infrastructure endpoint with firewall protections in place. SOC analysts should monitor for any changes in service availability or threat indicator emergence while considering the recommended blocking rules as a precautionary measure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | CHANDER PARKASH |
| ASN | AS152565 |
| Network Name | JOYSVC |
| CIDR Block | 163.61.38.0/24 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | nginx/1.24.0 |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 26% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 23% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 25% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:50 UTC |
| Last Seen | 2026-06-22 19:27:46 UTC |
| Profile Built | 2026-06-22 19:34:25 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.