# IP Intelligence Briefing: 59.103.113.9/32
Classification: LOW RISK
Generated: Current timestamp
Analyst: IPDebrief Intelligence Platform
---
## Executive Summary
IP 59.103.113.9 is classified as Low Risk with a risk score of 0. The address shows no active threat indicators, no open services, and operates within a clean neighborhood. No immediate blocking or filtering actions are required based on current intelligence.
---
## Ownership & Network Classification
- ASN: AS9541 (cyber internet services (pvt) ltd.)
- Organization: Munir Ahmed
- Netname: CYBERNET-PK
- RIR: APNIC
- CIDR Block: 59.103.126.0/24
- Network Classification: Firewalled / No Services
- Ownership Changes: 0 (stable ownership)
---
## Geolocation Intelligence
Primary Location: France (FR) - Marseille
Secondary Signal: Pakistan (PK) - Karachi, Punjab region
Observations:
- Geographic consensus: False (3 sources, conflicting data)
- Distance from primary source: 5,747.4 km
- ICMP validation: Blocked - unable to validate
- GeoPlausible: True
- Probe count: 0
*Note: Conflicting geolocation data suggests either routing anomalies or data source inconsistencies. Further validation recommended if location accuracy is critical.*
---
## Threat Indicators Assessment
| Indicator | Status |
|---|---|
| Tor Exit Node | No |
| Known Attacker | No |
| Spam Source | No |
| Blacklist Count | 0 |
| DNSBL Listed Count | 0 |
| Abuse Confidence Score | N/A |
| Threat Persistence | None |
| Campaign Correlation | None |
Threat Signals: 0 active indicators detected across all monitored feeds.
---
## Neighborhood Analysis (59.103.113.0/24)
- Abuse Density: 0 (Clean)
- Classification: Clean
- Total Siblings: 2
- Active Siblings: 0
- Threat Siblings: 0
- Neighbor Risk Profile: 59.103.113.100 - Risk Score: 0, Authority Score: 50
The /24 subnet shows no inherited risk and no active threat activity from neighboring addresses.
---
## Service & DNS Assessment
| Metric | Status |
|---|---|
| Open Ports | None detected |
| TLS Certificate | Not found |
| Hosted Domains | 0 |
| Forward Resolution | 0 |
| Email Authentication | SPF: No, DMARC: No |
| PTR Hostnames | None |
DNSSEC Valid: Yes
CAA Records: No
---
## Historical Signal Analysis
Total Observations: 18
Recent Activity: 2026-07-26 (most recent observation)
Signal Timeline:
- Port scanning: Multiple ports scanned (no open services confirmed)
- Geolocation signals: Mixed FR/PK readings with 70-85% confidence
- Network classification: Consistently non-cloud, non-proxy, non-VPN
- Threat observation count: 0
No evidence of escalating threat activity or pattern changes over time.
---
## Relationship Graph
Connected Entities: 3
- Type: Same Network (CYBERNET-PK)
- All relationships indicate same-network association with no external entity links detected.
---
## Recommended Security Actions
Current Risk Level: 0 (Low)
Recommended Actions: None required
Firewall Rules: No rules generated based on risk profile.
SOC Guidance: This IP does not require special attention or blocking. Standard monitoring applies. No positive identification for threat activity.
---
## Traceroute Summary
- Hop Count: 30
- First Hop RTT: 0.4 ms
- Last Hop RTT: 209.8 ms
- Timed Out Hops: 20
- Transit Networks: Comcast
---
## Conclusion
IP 59.103.113.9 presents as a benign, low-risk address with no active threat indicators, no open services, and a clean neighborhood profile. The conflicting geolocation data warrants monitoring but does not indicate malicious activity. No immediate action required.
---
Intelligence Platform: IPDebrief
Data Sources: Multiple intelligence feeds (Pulsedive, AlienVault-OTX, and proprietary sources)
Confidence Level: High
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Munir Ahmed |
| ASN | AS9541 |
| Network Name | CYBERNET-PK |
| CIDR Block | 59.103.126.0/24 |
| RIR | APNIC |
| Country | PK |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS9541 |
| Network Prefix | 59.103.113.0/24 |
| Route mapping | Found |
| Certificates in transparency logs | 0 certificates |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 18% | 5 | 5 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-11 20:39:43 UTC |
| Last Seen | 2026-09-02 16:37:52 UTC |
| Profile Built | 2026-09-02 16:40:17 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 59.103.113.9
Who owns the IP address 59.103.113.9?
59.103.113.9 is registered to Munir Ahmed. The address falls within the 59.103.126.0/24 network block. Registration is held at APNIC.
Where is 59.103.113.9 located?
Geolocation data places 59.103.113.9 in Marseille, Punjab, France. The local time zone is Europe/Paris. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 59.103.113.9 malicious or safe?
59.103.113.9 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.