IP Intelligence Briefing: 203.222.135.138
Date: 2026-06-07
---
**1. Risk Profile**
- Risk Score: 80 (High Risk)
- Provider: TPG Hostmaster (AS7545)
- Geolocation: Melbourne, Victoria, Australia (GPS: -37.81, 145.07)
- Network Classification: "Firewalled / No Services" (no open ports, no TLS/HTTP services detected)
- Threat Indicators: No direct malicious activity observed (no malware, phishing, or C2 indicators).
---
**2. Ownership & Network Context**
- Registrar: APNIC (TPG Hostmaster)
- Subnet: 203.222.128.0/19 (TPG-AU)
- Abuse Contact: Hostmaster@tpgtelecom.com.au
- BGP Prefix: 203.222.134.0/23
- Route Stability: Unstable (route changes in last 30 days).
---
**3. Threat Observations**
- DNSBL Listings:
- Listed in 5/8 DNSBLs (e.g., Spamhaus, OpenDNS, etc.).
- Risk Categories: "High" severity listings (exact sources omitted).
- Historical Activity:
- First observed May 30, 2026.
- No persistent malicious behavior (zero threat persistence days).
---
**4. Network Relationships**
- Linked Entities:
- Subnet: 203.222.128.0/19 (TPG-AU)
- No direct relationships to domains, organizations, or certificates.
- Neighbor Analysis:
- No sibling IPs in /24 subnet (likely a /32 host).
- Subnet abuse density: 1 (low risk).
---
**5. Behavioral & Technical Insights**
- DNS:
- PTR record: `203-222-135-138.tpgi.com.au`
- No SPF/DKIM records; no email authentication setup.
- Services:
- No open ports or active services detected.
- Control Plane:
- BGP route stability issues; RPKI invalid state.
---
**6. Recommendations**
- Monitoring:
- Track DNSBL status and subnet abuse density.
- Monitor for unexpected service exposure (e.g., TLS/HTTP ports).
- Mitigation:
- Consider blocking DNSBL-listed IPs in firewall rules.
- Verify TPG Hostmaster abuse contact for potential remediation.
Conclusion: The IP is part of a TPG network in Melbourne with no direct malicious activity but has historical DNSBL listings. While not actively malicious, its high risk score and unstable BGP routes warrant continued monitoring for potential abuse.
---
*Generated by IPDebrief. All data sourced from IP intelligence feeds and historical observations.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | TPG Hostmaster |
| ASN | AS7545 |
| Network Name | TPG-AU |
| CIDR Block | 203.222.128.0/19 |
| RIR | APNIC |
| Country | AU |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 203-222-135-138.tpgi.com.au |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 203-222-135-138.tpgi.com.au |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-dropbear_2018.76 ????T{???WE??????curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2- |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 38% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 13% | 1 | 1 |
| Overall | 22% | 8 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Fresh
| First Seen | 2026-05-16 02:55:09 UTC |
| Last Seen | 2026-06-26 18:11:05 UTC |
| Profile Built | 2026-06-22 08:16:42 UTC |
| Data Freshness | Fresh |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.