# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 203.128.29.115/32
Date: 2026-07-31
Classification: Moderate Risk (Score: 50)
---
## EXECUTIVE SUMMARY
IP 203.128.29.115 is a Pakistan-based infrastructure address with moderate risk scoring (50). The IP is owned by IRT-BRAINNET-PK (ASN 141342) in the BRAINNET-PK /24 block and shows no active threat indicators. While the address itself is clean, it is listed on 2 of 8 DNSBLs, and the subnet exhibits minimal threat activity.
---
## OWNERSHIP AND GEOLOCATION
Organization: IRT-BRAINNET-PK
ASN: AS141342
CIDR Block: 203.128.29.0/24
Geolocation: Karachi, Sindh, Pakistan (PK)
RIR: APNIC
Registration: No public registration date available
---
## THREAT PROFILE
Risk Score: 50 (Moderate)
Abuse Confidence: Null
Threat Indicators: None detected
Blacklist Status: Listed on 2 of 8 DNSBLs
Campaign Associations: None
Known Attacker: No
Tor Exit Node: No
Spam Source: No
Service Analysis: No open ports detected. Service classification: "Firewalled / No Services"
---
## NETWORK CONTEXT
Subnet Classification: Clean
Subnet Abuse Density: 0
Threat Siblings in /24: 0
Total Active Siblings: 2
Neighbor Risk Scores:
- 203.128.29.105: Risk 25 (Low)
- 203.128.29.152: Risk 25 (Low)
Control Plane:
- BGP Prefix: 203.128.29.0/24
- Route Stability: False
- RPKI State: Unknown
- Route Changes (30d): 0
---
## DNS INFRASTRUCTURE
PTR Hostname: 203-128-29-115.braintel.net.pk
Forward Resolution: Not confirmed
Hosted Domains: None
Email Authentication: SPF: No, DMARC: No
TXT Records: 0
---
## OBSERVATION HISTORY
Total observations: 16 signals recorded through 2026-07-31
Key Historical Signals:
- Subnet classification consistently "clean" with 0 abuse density
- Geolocation signals from multiple sources (MaxMind Geolite2, AlienVault OTX)
- Operator score: 0.1304 (Minimal risk)
- No persistent malicious behavior detected
---
## RELATIONSHIP MAPPING
Network Associations: BRAINNET-PK (3 entries)
DNS Associations: 203-128-29-115.braintel.net.pk (3 entries)
Organizations: IRT-BRAINNET-PK
Certificates: None
---
## RECOMMENDED ACTIONS
Firewall Rules (Block Recommended)
iptables:
```
iptables -A INPUT -s 203.128.29.115 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 203.128.29.115 drop
```
nginx:
```
deny 203.128.29.115;
```
pfSense:
```
203.128.29.115/32
```
Cloudflare WAF:
```json
{
"description": "Block 203.128.29.115 โ IPDebrief risk score 50",
"action": "block",
"filter": {
"expression": "ip.src eq 203.128.29.115"
}
}
```
AWS WAF:
```json
{
"Addresses": ["203.128.29.115/32"],
"Description": "IPDebrief risk 50"
}
```
---
## ANALYST NOTES
This address represents a firewalled infrastructure endpoint with no active services or open ports. While the IP itself shows no threat indicators, the DNSBL listings warrant monitoring. The subnet environment is relatively clean with no threat siblings detected. The moderate risk score (50) primarily reflects DNSBL listings rather than active malicious behavior. Recommend blocking at perimeter controls if not already in place.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-BRAINNET-PK |
| ASN | AS141342 |
| Network Name | BRAINNET-PK |
| CIDR Block | 203.128.29.0/24 |
| RIR | APNIC |
| Country | PK |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 203-128-29-115.braintel.net.pk |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 203-128-29-115.braintel.net.pk |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 50% | 2 | 3 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 23:20:25 UTC |
| Last Seen | 2026-08-01 22:41:44 UTC |
| Profile Built | 2026-07-31 05:01:51 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.