IPDebrief

106.192.16.173

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 106.192.16.173/32

## Executive Summary

IP address 106.192.16.173 presents a Moderate Risk profile (Risk Score: 40). The address is associated with Bharti Airtel mobile infrastructure in Hyderabad, India, with no active threat indicators currently observed. Recommended action is defensive blocking pending further contextual analysis.

## Ownership and Infrastructure

AttributeValue
ASN45609
OrganizationIRT-BHARTI-MO-IN (Bharti Airtel Ltd.)
Network NameMOHALI-UN
CIDR Block106.192.16.0/20
CountryIndia (IN)
RegionTelangana, Hyderabad
RIRAPNIC

The IP is classified as mobile infrastructure (Airtel carrier: LTE/5G) with no hosting, CDN, or proxy characteristics. The connection type is residential/mobile rather than enterprise infrastructure.

## Threat Assessment

Control Plane Data

## Network Neighborhood Analysis

Subnet: 106.192.16.173/24

The immediate /24 subnet shows no evidence of malicious activity or associated threat actors. No neighboring IPs flagged for abuse.

## Service and Port Analysis

The IP does not expose any services to the internet. No open ports or web application banners were observed during scanning.

## Historical Activity

15 observations recorded as of July 27, 2026:

Geo-validation shows ICMP blocked during probing, with a minimum possible RTT of 145ms from probe location. Geolocation data indicates consistent placement in Hyderabad, India.

## Related Entities

Three relationship entries identified, all pointing to the same network entity (MOHALI-UN). No external relationships to organizations, hostnames, or certificates were discovered.

## Recommended Actions

Based on the moderate risk score (40) and the recommendation to block:

Firewall Rules

```bash

# iptables

iptables -A INPUT -s 106.192.16.173 -j DROP

# nftables

nft add rule inet filter input ip saddr 106.192.16.173 drop

# nginx

deny 106.192.16.173;

# pfSense

106.192.16.173/32

# Cloudflare WAF

{"description":"Block 106.192.16.173 — IPDebrief risk score 40","action":"block","filter":{"expression":"ip.src eq 106.192.16.173"}}

# AWS WAF

{"Addresses":["106.192.16.173/32"],"Description":"IPDebrief risk 40"}

```

## Intelligence Summary

This IP belongs to Bharti Airtel's mobile network infrastructure in Hyderabad, India. While currently showing moderate risk characteristics (DNSBL listings, unstable routing), no active threat indicators, campaigns, or malicious behavior have been observed. The subnet is clean with no associated threat actors.

Recommendation: Implement blocking at the perimeter firewall level due to moderate risk score. Monitor for any changes in threat indicators or service exposure. Given the mobile carrier association, false positives are possible; correlate with legitimate traffic patterns before implementing permanent blocks.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇮🇳 India
RegionHP
CityYol
TimezoneAsia/Kolkata
Latitude17.38
Longitude78.46

🏢 Ownership & Registration

OrganizationIRT-BHARTI-MO-IN
ASNAS45609
Network NameMOHALI-UN
CIDR Block106.192.16.0/20
RIRAPNIC
CountryIN
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)

🔐 DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureMobile
Service PurposeFirewalled / No Services
Network TierUnknown — Insufficient routing data to classify
Mobile

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS45609
Network Prefix106.192.16.0/22
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
23%
24
routing
8%
11
services
12%
22
ownership
36%
25
reputation
20%
13
geolocation
17%
23
Overall19%1018
Coverage: 5/6 dimensions · Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-13 21:31:35 UTC
Last Seen2026-09-02 11:24:36 UTC
Profile Built2026-09-02 11:29:17 UTC
Data FreshnessLive
Signal Types19
Total Observations26
🔍 19 signal types · 26 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 106.192.16.173

Who owns the IP address 106.192.16.173?

106.192.16.173 is registered to IRT-BHARTI-MO-IN. The address falls within the 106.192.16.0/20 network block. Registration is held at APNIC.

Where is 106.192.16.173 located?

Geolocation data places 106.192.16.173 in Yol, HP, India. The local time zone is Asia/Kolkata. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 106.192.16.173 malicious or safe?

106.192.16.173 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

Is 106.192.16.173 a VPN, proxy, or data center address?

106.192.16.173 is classified as a mobile network based on network ownership and behavioural analysis.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.