# IP Intelligence Briefing: 43.225.68.34/32
## Executive Summary
IP 43.225.68.34 presents a moderate-risk threat profile (55/100) with elevated DNSBL listings and conflicting geolocation data. The IP is classified as "clean" at the /24 subnet level but requires enhanced monitoring due to blacklist associations and risk indicators.
## Risk Assessment
- Overall Risk Score: 55/100 (Moderate Risk)
- Reputation: Moderate Risk
- Control Plane Status: Unstable routing (isRouteStable: false)
- DNSBL Listings: 3 of 8 total blacklist entries
- Abuse Confidence: No direct threat indicators detected
## Technical Profile
- ASN: 59162 (UPCSPL-AS-IN - U.P. COMMUNICATION SERVICES PVT LTD, IN)
- Geolocation: Newark, New Jersey, US (US-NJ)
- CIDR Block: 43.225.68.0/24
- Network Role: Firewalled / No Services
- Open Ports: None detected
- Reverse DNS: No PTR records found
## Threat Indicators
- DNSBL Presence: Listed on 3 threat feeds with high severity maximum
- Campaign Activity: No known campaign associations
- Known Attacker: Not identified
- Tor Exit Node: No
- Spam Source: No
- Historical Threat Persistence: 0 days (no persistent malicious activity detected)
## Historical Observations (11 observations)
Recent activity shows conflicting signals:
- Geolocation: Traced to Newark, US-NJ via hop_ip 62.115.138.58
- ASN Routing: APNIC-registered ASN 59162 (India-based registry)
- DNSSEC: Validated
- Traceroute: 17 hops, 3 time-outs, transit networks include Comcast and Cogent
## Subnet Neighborhood Analysis
- Subnet: 43.225.68.0/24
- Abuse Density: 0.0 (clean)
- Threat Siblings: 0
- Active Siblings: 0
- Classification: Clean subnet with inherited risk of 0
## Recommended Actions
SOC Analyst Priority: MEDIUM
1. Logging: Increase logging verbosity for traffic from this IP address
2. Firewall Blocking: Consider blocking at perimeter based on risk score 55/100
3. Monitoring: Track for any changes in behavior or service exposure
Recommended Firewall Rules:
- iptables: `iptables -A INPUT -s 43.225.68.34 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 43.225.68.34 drop`
- nginx: `deny 43.225.68.34;`
- Cloudflare WAF: Block IP with expression `ip.src eq 43.225.68.34`
- AWS WAF: Add IP 43.225.68.34/32 to block list
## Intelligence Conclusion
While the /24 subnet shows no abuse activity, the target IP warrants monitoring due to DNSBL associations and unstable routing behavior. The IP shows no active threat indicators but maintains elevated risk through blacklist listings. Recommend continued observation and potential blocking pending additional correlation with internal threat intelligence.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | UMESH BAGHEL |
| ASN | AS59162 |
| Network Name | UPIPL |
| CIDR Block | 43.225.68.0/22 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | lighttpd/1.4.39 |
| HTTP Title | โ |
| SSH Version | SSH-2.0-dropbear <,{???gd?=T?|;???curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-gro |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 8% | 2 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-24 20:34:18 UTC |
| Last Seen | 2026-08-04 05:42:59 UTC |
| Profile Built | 2026-08-02 11:01:36 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 19 |
Full dossier details are available via our API.