# IP Intelligence Briefing: 59.103.222.123/32
## Executive Summary
The IP address 59.103.222.123 presents a moderate risk profile (score: 40) with conflicting geolocation data and DNSBL listings. The address is registered to PTCL (Pakistan Telecommunication Company Limited) but displays geolocation inconsistencies between Pakistan and France. No active services are detected, and the subnet maintains low abuse density.
## Risk Profile
- Overall Risk Score: 40 (Moderate Risk)
- ASN: 141031 (PTCL)
- Organization: Munir Ahmed
- Geolocation Discrepancy: Profile indicates France (FR, Marseille), while historical signals consistently point to Pakistan (PK, Lahore/Karachi region)
- Classification: Firewalled/No Services
- DNSBL Status: Listed on 2 of 8 threat feeds
## Network Context
Subnet Analysis (59.103.222.0/24):
- Abuse Density: 0 (Clean)
- Neighbor IP: 59.103.222.9 (Risk Score: 40)
- Subnet Classification: Clean
- Total Siblings: 2
## Threat Indicators
- Tor Exit: No
- Known Attacker: No
- Spam Source: No
- Campaign Associations: None detected
- Certificate Matches: 0
## Observation History (17 observations)
Recent signals (2026-07-26) indicate:
- Geo-location signals from Lahore and Karachi, Pakistan
- One signal detected by AlienVault OTX referencing Pakistan coordinates
- No persistent malicious activity observed
- Ownership stability: No changes recorded
## Network Behavior
- Open Ports: None detected
- DNS Records: No PTR records, no forward resolution
- Email Authentication: No SPF or DMARC records
- Control Plane: Route instability detected, RPKI state unknown
- BGP Prefix: 59.103.222.0/24
## Recommended Actions
Based on the risk profile, the following firewall rules are recommended:
iptables:
```
iptables -A INPUT -s 59.103.222.123 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 59.103.222.123 drop
```
nginx:
```
deny 59.103.222.123;
```
Cloudflare WAF: Block with expression `ip.src eq 59.103.222.123`
AWS WAF: Block IP 59.103.222.123/32
## Intelligence Assessment
The IP exhibits moderate risk characteristics with notable geolocation inconsistencies. The address appears to be part of a residential ISP allocation (PTCL) with no active services currently running. The DNSBL listings warrant attention, though the overall subnet maintains low abuse density. Recommend blocking at perimeter if internal policy supports moderate-risk mitigation. Monitor for changes in geolocation consistency and service activation.
---
*This briefing is based on data from IPDebrief intelligence platform. All recommendations should be validated against organizational policy and additional threat intelligence sources.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Munir Ahmed |
| ASN | AS141031 |
| Network Name | PTCL |
| CIDR Block | 59.103.216.0/21 |
| RIR | APNIC |
| Country | PK |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS141031 |
| Network Prefix | 59.103.222.0/24 |
| Route mapping | Found |
| Certificates in transparency logs | 0 certificates |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 21% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 17% | 2 | 3 |
| reputation | 8% | 1 | 2 |
| geolocation | 12% | 2 | 2 |
| Overall | 13% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-11 20:39:43 UTC |
| Last Seen | 2026-09-03 22:07:31 UTC |
| Profile Built | 2026-09-03 22:08:59 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 59.103.222.123
Who owns the IP address 59.103.222.123?
59.103.222.123 is registered to Munir Ahmed. The address falls within the 59.103.216.0/21 network block. Registration is held at APNIC.
Where is 59.103.222.123 located?
Geolocation data places 59.103.222.123 in Marseille, Punjab, France. The local time zone is Europe/Paris. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 59.103.222.123 malicious or safe?
59.103.222.123 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.