## IP Intelligence Briefing: 203.150.243.32/32
Classification: Moderate Risk | Jurisdiction: Thailand | Reporting Date: 2026-07-31
---
Executive Summary
IP 203.150.243.32 is classified as Moderate Risk (65/100) and is associated with INET-TH (INET NOC ROLE), a Thai infrastructure provider. The IP is classified as "Firewalled / No Services" with no open ports detected. Despite minimal operator classification (0.1304) and a clean neighborhood (0% abuse density), the IP appears on 3 of 8 DNS blacklists, warranting elevated monitoring.
---
Ownership and Registration
- ASN: 4618 (INET NOC ROLE / INET-TH)
- CIDR Block: 203.150.128.0/17
- Organization: INET NOC ROLE
- RIR: APNIC
- Geolocation: Khet Huay Khwang, Thailand (13.74°N, 100.46°E)
---
Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 65/100 |
| **Open Ports** | None detected |
| **DNSSEC** | Valid |
| **RPKI State** | Not available |
| **Route Stability** | Unstable |
| **BGP Prefix** | 203.150.243.0/24 |
| **Control Plane** | Firewalled / No Services |
---
Threat Indicators
- Blacklist Status: Listed on 3 of 8 DNS blacklists
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Association: No active campaigns identified
---
Neighborhood Analysis (203.150.243.0/24)
- Abuse Density: 0%
- Total Neighbors: 2
- Risk Distribution: 1 medium risk, 1 low risk
- Notable Neighbor: 203.150.243.8 (Risk Score: 40)
The subnet shows minimal abuse activity, with the subject IP standing as the highest-risk endpoint in the neighborhood.
---
Observation History
Sixteen signals observed over the monitoring period. Recent observations indicate:
- Classification: Clean
- Inherited Risk: 0
- Active Siblings: 1
- No persistent malicious activity detected
---
Relationships
- Network Association: INET-TH (INET-TH)
- DNS Associations: 32.243.150.203.sta.inet.co.th
---
Recommended Actions
Priority: High
1. Increase logging verbosity and review recent activity from this IP due to elevated risk score (65/100) and blacklist presence.
2. Implement blocking rules on perimeter infrastructure:
- iptables: `iptables -A INPUT -s 203.150.243.32 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 203.150.243.32 drop`
- nginx: `deny 203.150.243.32;`
- pfSense: `203.150.243.32/32`
- Cloudflare WAF: Block with filter expression `ip.src eq 203.150.243.32`
- AWS WAF: Add `203.150.243.32/32` to IP set
---
Analyst Notes
The IP lacks open services but maintains a moderate risk profile driven by blacklist listings. The absence of open ports suggests this may be a gateway or firewall device rather than an active attack source. However, the blacklist presence indicates prior or ongoing reputation issues that warrant continued monitoring. Recommend correlation with internal threat data before implementing permanent blocks.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | INET NOC ROLE |
| ASN | AS4618 |
| Network Name | INET-TH |
| CIDR Block | 203.150.128.0/17 |
| RIR | APNIC |
| Country | TH |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 32.243.150.203.sta.inet.co.th |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 32.243.150.203.sta.inet.co.th |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_7.2p2 Ubuntu-4ubuntu2.10 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 50% | 2 | 3 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 23:20:25 UTC |
| Last Seen | 2026-08-01 16:33:29 UTC |
| Profile Built | 2026-07-31 05:01:51 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 21 |
Full dossier details are available via our API.