## IP INTELLIGENCE BRIEFING: 105.113.64.227/32
Classification: Low Risk / Legitimate Infrastructure
Analysis Date: Current
Source: IPDebrief Threat Intelligence Platform
---
EXECUTIVE SUMMARY
IP address 105.113.64.227 is a low-risk address owned by Airtel Networks Limited (ASN 36873) in Lagos, Nigeria. The address is part of a legitimate telecom infrastructure block (105.112.0.0/12) and shows no active malicious behavior, blacklist associations, or threat indicators. No services are detected on the IP, indicating it is likely a firewalled network infrastructure address.
---
OWNERSHIP AND GEOLOCATION
| Attribute | Value |
|---|---|
| **IP Address** | 105.113.64.227/32 |
| **ASN** | 36873 |
| **Organization** | Airtel Networks Limited |
| **Netname** | ORG-VNL1-AFRINIC |
| **Country** | Nigeria (NG) |
| **Region/City** | Lagos, Lagos |
| **RIR** | AFRINIC |
| **CIDR Block** | 105.112.0.0/12 |
---
RISK ASSESSMENT
Overall Risk Score: 25 (Low Risk)
Risk Breakdown:
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
Threat Indicators:
- Blacklist Count: 0
- Abuse Confidence Score: N/A
- Is Tor Exit: No
- Is Known Attacker: No
- Is Spam Source: No
- Known Campaigns: None detected
---
NETWORK CLASSIFICATION
- Network Role: Firewalled / No Services
- Infrastructure Type: Not detected
- Cloud Service: No
- CDN: No
- VPN: No
- Proxy: No
- Hosting Provider: No
- Mobile Network: No
- Residential: No
---
DNS AND SERVICE ANALYSIS
- PTR Records: None resolved
- Forward Resolution: No reverse DNS entries
- Open Ports: None detected
- TLS Certificate: None
- HTTP Service: None detected
- Hosted Domains: None
- Email Authentication: SPF: Not configured, DMARC: Not configured
- DNSSEC Valid: Yes
---
CONTROL PLANE METRICS
- BGP Prefix: 105.113.64.0/24
- Route Stability: Not stable
- Route Changes (30d): 0
- DNSBL Listings: 1 of 8 lists (requires verification)
- Operator Score: 0.1304 (Minimal)
- RPKI State: Not reported
---
NEIGHBORHOOD ANALYSIS (105.113.64.0/24)
| Metric | Value |
|---|---|
| **Subnet Size** | /24 |
| **Total Siblings** | 2 |
| **Abuse Density** | 0 |
| **High Risk Neighbors** | 0 |
| **Medium Risk Neighbors** | 0 |
| **Low Risk Neighbors** | 0 |
Identified Neighbors:
- 105.113.64.64 (Risk Score: N/A)
- 105.113.64.140 (Risk Score: N/A)
---
OBSERVATION HISTORY
Total Observations: 10 (as of 2026-07-25)
Recent Signal Summary:
- Network classification signals detected with confidence levels ranging from 0.21 to 0.85
- No persistent malicious activity detected
- Threat persistence days: 0
- Ownership changes: 0
---
BEHAVIORAL ANALYSIS
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: 0
- Auto-Banned: No
- Threat Persistence: Not persistently malicious
---
TEMPORAL ANALYSIS
| Metric | Value |
|---|---|
| **Ownership Changes** | 0 |
| **Avg Ownership Days** | N/A |
| **Threat Persistence Days** | 0 |
| **Threat Observation Count** | 0 |
| **Is Persistently Malicious** | No |
---
CAMPAIGN CORRELATION
- Campaign Likelihood: N/A
- CERT Matches: 0
- Banner Matches: 0
- Correlated IPs: 0
- Known CERT Subjects: None
---
GEOLOCATION VALIDATION
| Metric | Value |
|---|---|
| **Geo-Plausible** | No |
| **Distance (km)** | N/A |
| **Minimum RTT (ms)** | N/A |
| **Average RTT (ms)** | N/A |
| **Probe Count** | 0 |
| **Geo Violation** | None reported |
---
FINGERPRINTING ANALYSIS
- Server Fingerprint: Not detected
- HTTP Status Code: N/A
- HSTS Enabled: No
- CSP Enabled: No
- HTTP/2 Support: No
- Favicon Hash: N/A
- Body Hash: N/A
- Powered By: Not detected
- Generator: Not detected
- TTFB (ms): N/A
- HTTP Version: Not detected
- Referrer Policy: Not detected
- Permissions Policy: Not detected
- Header Order: Not analyzed
---
EMAIL REPUTATION
- Email Reputation Score: N/A
- Has Score: No
- Sender Score: N/A
---
TRACEROUTE ANALYSIS
- Hop Count: 0
- First Hop RTT (ms): N/A
- Last Hop RTT (ms): N/A
- Timed Out Hops: 0
- Transit Networks: None reported
---
ACTIONS AND RECOMMENDATIONS
SOC Analyst Guidance:
1. Traffic Treatment: Monitor but no immediate blocking required based on current data
2. Threat Status: No active threat indicators detected
3. Investigation Priority: Low - infrastructure address with no malicious activity
4. Blocklist Verification: Review the single DNSBL listing if traffic from this IP is being rejected
Evidence Sources:
- No specific threat indicators or abuse reports available
- All behavioral metrics indicate legitimate infrastructure usage
---
SUMMARY
IP 105.113.64.227 is classified as low-risk infrastructure belonging to Airtel Networks Limited in Lagos, Nigeria. The address is not associated with any known malicious campaigns, does not host open services, and shows no behavioral indicators of compromise. SOC teams may monitor traffic from this address but no defensive actions beyond standard baseline monitoring are warranted at this time.
Report Generated: IPDebrief Intelligence Platform
Status: Clear for Continued Operation
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Airtel Networks Limited |
| ASN | AS36873 |
| Network Name | ORG-VNL1-AFRINIC |
| CIDR Block | 105.112.0.0/12 |
| RIR | AFRINIC |
| Country | NG |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS36873 |
| Network Prefix | 105.113.64.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 1 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-09 13:30:53 UTC |
| Last Seen | 2026-08-27 03:42:14 UTC |
| Profile Built | 2026-08-29 06:11:01 UTC |
| Data Freshness | Live |
| Signal Types | 13 |
| Total Observations | 14 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 105.113.64.227
Who owns the IP address 105.113.64.227?
105.113.64.227 is registered to Airtel Networks Limited. The address falls within the 105.112.0.0/12 network block. Registration is held at AFRINIC.
Where is 105.113.64.227 located?
Geolocation data places 105.113.64.227 in Lagos, Lagos, Nigeria. The local time zone is Africa/Lagos. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 105.113.64.227 malicious or safe?
105.113.64.227 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.