# IPDEBRIEF INTELLIGENCE BRIEFING
Target IP: 106.214.9.202/32
Classification: Low Risk / Mobile Origin
Date: July 2026
## Executive Summary
IP 106.214.9.202 is a low-risk mobile-originated address assigned to Bharti Airtel's network infrastructure. The address exhibits minimal threat activity with a risk score of 25 and no active malicious indicators. The subnet shows predominantly clean classification with low abuse density (7.69%), indicating this IP operates within a legitimate residential/mobile carrier environment.
## Ownership and Network Context
- ASN: 24560 (Bharti Airtel Ltd.)
- Organization: Rahul Jain / BHARTI-MO-IN
- CIDR Block: 106.192.0.0/11
- RIR: APNIC (Asia Pacific)
- Geolocation: India, Bihar, Saidpur (1500km accuracy radius)
- Network Classification: Mobile (LTE/5G technology via Airtel carrier, MCC: 404, MNC: 10)
- Connection Type: Mobile carrier traffic (not infrastructure/hosting)
## Threat Assessment
- Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not applicable (no active abuse signals)
- Known Threat Indicators: None
- Blacklist Status: Listed on 1 of 8 DNSBLs
- Tor/Proxy/VPN: Not identified as Tor exit node, proxy, or VPN endpoint
- Active Threat Feeds: None
- Known Campaigns: None identified
## Network Services and Infrastructure
- Open Ports: None detected
- TLS Certificate: Not applicable
- HTTP Services: None detected (firewalled/no services)
- DNS Resolution: No forward resolution (no reverse hostname)
- Email Authentication: No SPF/DMARC records (non-mail role)
## Neighborhood Analysis (106.214.9.0/24)
- Total Siblings: 39
- Active Siblings: 18
- Threat Siblings: 3
- Abuse Density: 0.0769 (7.69%)
- Subnet Classification: Mostly clean
- Inherited Risk Score: 3
- Risk Distribution: 34 low risk, 0 medium, 0 high risk
Neighbor IP 106.214.9.202 exhibits similar risk characteristics to peers in the subnet, with the majority showing risk scores of 0 or 25. No high-risk neighbors were identified.
## Observation History
- Total Observations: 15 signals
- Recent Activity: Scans and network probes observed within the past 10 minutes
- Geolocation Consensus: India (52% confidence, multi-signal inference)
- Traceroute: 30 hops to target, did not reach target (timed out)
- Threat Persistence: 0 days
- Ownership Changes: 0 (stable assignment)
The IP shows transient mobile carrier activity patterns with no persistent malicious behavior detected across the observation window.
## Control Plane Metrics
- BGP Prefix: 106.214.9.0/24
- Route Stability: Unstable (isRouteStable: false)
- Operator Score: 0.1304 (Minimal)
- RPKI State: Not verified
- DNSSEC: Valid
## Recommended Actions
No specific firewall rules or blocking actions are recommended at this time. The IP presents a low-risk profile consistent with legitimate mobile carrier traffic. If traffic from this IP requires filtering:
- Allow: Standard mobile carrier traffic patterns
- Monitor: Unusual port scans or service enumeration attempts
- Block: Only if associated with confirmed malicious activity
## Intelligence Conclusion
IP 106.214.9.202 is a mobile-originated address within Bharti Airtel's network infrastructure. The low risk score, clean neighborhood profile, and absence of active threat indicators support classification as legitimate mobile carrier traffic. No immediate action required unless specific suspicious activity patterns are observed at the network level.
---
*Generated by IPDebrief Intelligence Analysis Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Rahul Jain |
| ASN | AS24560 |
| Network Name | BHARTI-MO-IN |
| CIDR Block | 106.192.0.0/11 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 50% | 2 | 3 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 19:31:53 UTC |
| Last Seen | 2026-07-29 14:31:50 UTC |
| Profile Built | 2026-07-29 14:45:00 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.