INTELLIGENCE BRIEFING: 106.192.235.222/32
OVERVIEW
IP address 106.192.235.222 is classified as Moderate Risk with an overall risk score of 40. The address is geolocated to Bengaluru, Karnataka, India, within the AS45609 Bharti Airtel network infrastructure.
TECHNICAL PROFILE
- Network Classification: The IP operates as a firewalled address with no publicly accessible services detected. Open ports analysis returned empty, indicating either strict egress filtering or a dormant host.
- Ownership: Assigned to ASN 45609 (Bharti Airtel), with BGP prefix 106.192.232.0/22. The address is part of a stable routing delegation with operator score of 0.1304 (Minimal).
- DNS Status: Forward resolution is not confirmed. No PTR hostnames or reverse DNS records exist. The IP hosts no domains and lacks email authentication records (SPF/DMARC absent).
- Control Plane: The address is listed on 2 of 8 DNSBLs, indicating some historical reputation concerns. Route stability is flagged as unstable despite zero route changes in the past 30 days.
THREAT INDICATORS
- Abuse Indicators: No active threat indicators detected. The IP is not identified as a Tor exit node, known attacker, spam source, or part of any known malicious campaigns.
- Blacklist Status: Zero blacklist entries reported in current threat feeds.
- Behavioral Signals: No honeypot hits, enumeration strikes, or WAF violations observed. The IP is not currently classified as an active attacker.
OBSERVATION HISTORY
Recent observations (July 27, 2026) show temporal variability in geolocation data. Multiple sources reported conflicting locations within India, including Bengaluru (Karnataka), Shimla (HP), and coordinates at 20.59°N, 78.96°E. This geographic dispersion is consistent with Indian mobile carrier networks utilizing dynamic addressing or proxy infrastructure.
NETWORK CONTEXT
- /24 Neighborhood: The 106.192.235.0/24 subnet shows zero abuse density with no detected sibling IPs. No threat siblings or active neighbors identified.
- Relationships: No correlated entities, certificates, or related hostnames detected in the relationship graph.
RECOMMENDED ACTIONS
Based on the risk profile, the following defensive measures are recommended:
- Firewall: Block inbound traffic from 106.192.235.222/32 across perimeter networks.
- WAF/Cloud Security: Apply block rules on Cloudflare WAF and AWS WAF with the rationale "IPDebrief risk score 40".
- Implementation: Rules compatible with iptables, nftables, pfSense, and nginx are available for immediate deployment.
ASSESSMENT
This IP presents a moderate risk profile primarily due to DNSBL listings and geographic inconsistency in observed data. The lack of open services and threat indicators suggests the address may be dormant, repurposed, or used for non-public traffic. No immediate threat activity is observable, but the DNSBL presence warrants monitoring for renewed malicious activity.
CLASSIFICATION: Moderate Risk – Monitor with blocking recommended for defensive posture.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-BHARTI-MO-IN |
| ASN | AS45609 |
| Network Name | MOHALI-UN |
| CIDR Block | 106.192.224.0/20 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS45609 |
| Network Prefix | 106.192.232.0/22 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 34% | 2 | 6 |
| reputation | 20% | 1 | 3 |
| geolocation | 17% | 2 | 3 |
| Overall | 20% | 10 | 19 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-12 21:05:57 UTC |
| Last Seen | 2026-09-05 22:39:44 UTC |
| Profile Built | 2026-09-05 23:24:05 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 30 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 106.192.235.222
Who owns the IP address 106.192.235.222?
106.192.235.222 is registered to IRT-BHARTI-MO-IN. The address falls within the 106.192.224.0/20 network block. Registration is held at APNIC.
Where is 106.192.235.222 located?
Geolocation data places 106.192.235.222 in Shimla, HP, India. The local time zone is Asia/Kolkata. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 106.192.235.222 malicious or safe?
106.192.235.222 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
Is 106.192.235.222 a VPN, proxy, or data center address?
106.192.235.222 is classified as a mobile network based on network ownership and behavioural analysis.