# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 106.214.9.99/32
Classification: Low Risk / Passive
Report Date: 2026-07-30
Analyst: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
IP 106.214.9.99 presents as a low-risk, geofenced passive endpoint located in Saidpur, Bihar, India. The IP exhibits no active service exposure, no detected threat indicators, and demonstrates stable operational characteristics within its /24 subnet. Current risk assessment: 25 (Low Risk).
---
## GEOLOCATION & INFRASTRUCTURE
- Location: Saidpur, Bihar, India (25.61°N, 85.63°E)
- ASN: 24560
- BGP Prefix: 106.214.9.0/24
- Timezone: Asia/Kolkata
- Network Role: Firewalled / No Services Detected
Multiple geolocation sources corroborate the India/Bihar/Saidpur assignment with consistent coordinate data. The IP maintains minimal operator score (0.1304) indicating low-activity infrastructure.
---
## THREAT ASSESSMENT
| Metric | Status |
|---|---|
| Risk Score | 25 (Low Risk) |
| Abuse Confidence Score | Not Reported |
| Blacklist Count | 0 |
| Threat Feeds | None |
| Known Campaigns | None |
| Is Tor Exit | No |
| Is Known Attacker | No |
| Is Spam Source | No |
Assessment: No active threat indicators detected. IP is not associated with known malicious campaigns or threat actor infrastructure.
---
## NETWORK BEHAVIOR
- Open Ports: None detected
- TLS/HTTP Services: None
- DNS Records: No forward resolution
- PTR Hostnames: None
- Email Auth: SPF/DMARC not configured
- Control Plane: 1 DNSBL listing (8 total evaluated)
---
## TEMPORAL ANALYSIS
Observation History: 10 signals recorded over monitoring period. Recent observations (2026-07-30) confirm persistent geolocation data from multiple sources (MaxMind, Cymru). ICMP validation probes blocked; route stability flagged as unstable.
Persistence Metrics:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Is Persistently Malicious: No
---
## NEIGHBORHOOD ANALYSIS (106.214.9.0/24)
Subnet Profile:
- Total Siblings: 39 IPs
- Abuse Density: 0
- Risk Distribution: 0 High | 2 Medium | 35 Low
Notable Neighbors:
- 106.214.9.38: Risk Score 40 (Elevated)
- 106.214.9.212: Risk Score 40 (Elevated)
- Majority: Risk Score 25 or 0 (Low/No Risk)
Assessment: The /24 subnet demonstrates low overall abuse density. Target IP shares risk characteristics (score 25) with 34 of 39 neighbors, suggesting consistent operational profile within the subnet.
---
## RELATIONSHIP GRAPH
- Detected Relationships: 0
- Associated Hostnames: None
- Associated Organizations: None
- Associated Certificates: None
---
## SECURITY ACTIONS
No specific firewall or blocking actions recommended based on current risk profile. IP classified as passive infrastructure with no active threat indicators.
Recommended Monitoring: Continue baseline observation. No immediate mitigation required.
---
## CONCLUSION
IP 106.214.9.99 operates as a low-risk endpoint with no active threat indicators. The absence of open services, combined with the subnet's low abuse density, indicates this IP is either legitimately operational defensive infrastructure or passive. No immediate action required.
---
*Report generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Rahul Jain |
| ASN | AS24560 |
| Network Name | BHARTI-MO-IN |
| CIDR Block | 106.192.0.0/11 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-28 22:21:31 UTC |
| Last Seen | 2026-07-30 18:36:27 UTC |
| Profile Built | 2026-07-30 18:48:49 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.