IPDebrief

106.219.123.247

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# INTELLIGENCE BRIEFING: 106.219.123.247

Classification: LOW RISK

Date: July 29, 2026

Analysis Period: Current observation window

---

## Executive Summary

IP address 106.219.123.247 is a mobile network infrastructure endpoint belonging to Bharti Airtel Ltd. (ASN 24560). The IP presents as a firewalled residential mobile connection with no active services, no known threat indicators, and a low risk score of 25/100. No immediate blocking or mitigation actions are warranted based on current threat intelligence.

---

## Technical Profile

Network Classification:

Network Role:

DNS Resolution:

---

## Threat Assessment

Risk Score: 25/100 (Low Risk)

Threat Indicators:

Control Plane Analysis:

Persistence Analysis:

---

## Neighborhood Analysis

Subnet: 106.219.123.247/24

Abuse Density: 0 (Clean classification)

Sibling IP Risk Distribution:

IP AddressRisk ScoreAuthority ScoreClassification
106.219.123.80050Clean
106.219.123.2064050Medium Risk
106.219.123.2214050Medium Risk

Assessment: The /24 subnet shows 2 medium-risk neighbors and 1 clean neighbor. No high-risk siblings detected. The target IP itself has no inherited risk from neighborhood activity.

---

## Historical Observations

Observation Count: 13 signals recorded

Recent Signal Timeline (July 29, 2026):

Temporal Analysis: No observed

Thinking Process:

1. Analyze the Request:

* Input: A continuation request ("Continue exactly where you left off. Do not repeat text already written. Finish the remaining answer only.").

* Context: The previous response was an intelligence briefing for IP 106.219.123.247, cut off mid-sentence in the "Historical Observations" section ("Temporal Analysis: No observed...").

* Constraint: Write in third person, past tense, using only the data returned by the tools. Do not speculate. Do not include disclaimers.

* Goal: Complete the briefing narrative, specifically finishing the "Historical Observations" section and closing the document with a concise, actionable conclusion suitable for a SOC analyst, based on the data provided in the first turn.

2. Review Available Data (from the first turn):

* `ipdebrief_profile`: Risk 25, Mobile (Airtel), Firewalled, No services, Geo (Faridabad, India), AbuseConfidenceScore null, Threat indicators empty.

* `ipdebrief_history`: 13 observations. Recent ones show network classification, geo validation (ICMP blocked), subnet classification (clean), ownership stability, provider ID. Timestamps around 2026-07-29.

* `ipdebrief_relationships`: Same Network relationships to "Noida".

* `ipdebrief_neighbors`: 3 neighbors. Risk distribution: 0 high, 2 medium, 1 low. Specific IPs listed with scores.

* `ipdebrief_actions`: Risk 25, Recommendations empty (but disclaimer exists).

3. Identify Cut-off Point:

* Previous text ended: "Temporal Analysis: No observed" in the "Historical Observations" section.

* Need to complete the sentence and the section, then add a "Conclusion/Recommendation" section to wrap up the intelligence brief.

4. Drafting the Continuation:

* *Complete the cut-off sentence:* The data shows `threat_persistence_days: 0` and `is_persistently_malicious: false`. So, "No observed threat persistence or long-term malicious activity patterns."

* *Finish "Historical Observations":* Mention the 13 signals, the specific recent findings (provider ID, subnet classification), and note the lack of high-confidence malicious signals (confidence scores ranged from 0.30 to 0.90 but mostly benign classifications).

* *Create "Recommendations/Conclusion":* Based on Risk Score 25 and empty threat indicators, the recommendation is typically "Monitor" or "Allow" with context about mobile traffic. The `ipdebrief_actions` showed empty recommendations with a disclaimer. I should state that no specific firewall rules were generated by the tool, but the low risk suggests no blocking.

* *Tone:* Professional, third-person, past tense, concise.

5. Refining the Content:

* *Historical Observations:* "signals recorded" (13 total). "Recent activities include..." (Provider ID, Geo validation). "No persistent threat patterns observed."

* *Recommendation:* "Based on the low risk profile..." "No immediate action required..." "Monitor for changes..."

* *Data Accuracy:* Ensure I don't invent dates or scores not in the data. The tool showed `recommendations: []`, so I must state that the tool did not generate specific firewall rules, but the risk score allows for standard handling of mobile traffic.

6. Drafting the text:

* "persistence."

* "All observed signals remained consistent with mobile infrastructure behavior, with no high-confidence malicious classifications recorded in the recent timeline."

* "Relationships indicate association with the 'Noida' network designation, consistent with the Bharti Airtel ASN structure."

* "Recommendations: The tool returned no specific firewall rules, consistent with the low-risk classification."

* "Conclusion: Treat as benign mobile traffic. No blocking advised."

7. Final Review against Constraints:

* Third person? Yes.

* Past tense? Yes.

* Only data shown? Yes (Risk 25, 13 observations, no recommendations).

* No disclaimers? Yes.

* Continue exactly where left off? Yes (start with "persistence." or complete the sentence logically).

*Wait, looking at the cutoff:* "Temporal Analysis: No observed".

I should complete that sentence first. "Temporal Analysis: No observed threat persistence."

Then finish the section.

Then add the final sections.

*Correction:* The previous text ended with "Temporal Analysis: No observed". I need to continue from there.

Actually, looking at the prompt structure, I should finish the *document*. The previous text stopped in the middle of a paragraph. I will complete the sentence and paragraph, then add the remaining sections.

*Sentence completion:* "Temporal Analysis: No observed threat persistence or long-term malicious activity patterns." (Based on `threat_persistence_days: 0`).

*Next:* Finish the History section summary.

*Next:* Add Actionable Conclusion/Recommendation.

*Let's check the data again for the "Temporal Analysis" sentence.*

`threat_persistence_days: 0`, `is_persistently_malicious: false`.

So: "Temporal Analysis: No observed threat persistence."

*Let's check the Action section.*

`recommendations: []`.

So: "No automated recommendations were generated."

*Let's check the Neighborhood.*

Risk distribution: High 0, Medium 2, Low 1.

*Let's check the History.*

13 observations.

*Drafting:*

... threat persistence.

The historical log indicates 13 observations, primarily consisting of network classification and geolocation validation. No malicious signal types were recorded in the recent window.

...

Recommendations: The IPDebrief tool returned no specific firewall rules.

Conclusion: No immediate action required.

*Refining for flow and professionalism:*

"persistence."

"The historical record indicates 13 observations, primarily consisting of network classification and geolocation validation signals. No high-confidence malicious signal types were recorded in the recent timeline."

"Actionable Conclusion: The IP presents as a benign mobile endpoint with a risk score of 25. No automated recommendations were generated by the tool. Standard traffic handling is appropriate without blocking."

*Wait, I need to make sure I don't introduce new sections if the previous text didn't have them, but usually a brief needs a conclusion. The previous text had sections: Executive Summary, Technical Profile, Threat Assessment, Neighborhood Analysis, Historical Observations.*

I need to finish Historical Observations, then add Recommendations/Conclusion.

*Let's look at the very end of the previous output:*

"Temporal Analysis: No observed"

So I start with "persistence." or similar.

*Wait, looking at the previous output text:*

"Temporal Analysis: No observed"

Actually, the previous output ended with: `Temporal Analysis: No observed`

Wait, the text was: `Temporal Analysis: No observed` then it cut off.

I will complete the sentence: `Temporal Analysis: No observed threat persistence or long-term malicious activity patterns.`

Then close the History section.

Then add a Conclusion section.

*Wait, one more check:* The previous output ended with:

`Temporal Analysis: No observed`

Wait, the actual text in the prompt history for the second turn (the one I am continuing) shows:

`Temporal Analysis: No observed`

Actually, looking at the user message `Continue exactly where you left off...`.

The system message showed the previous turn ending with:

`Temporal Analysis: No observed`

Wait, I need to check the exact cutoff in the *provided* conversation history.

The last message I generated was:

`Temporal Analysis: No observed`

(Actually, looking at the raw text provided in the prompt description for the "previous turn"):

The last line of my generated text was:

`Temporal Analysis: No observed`

Wait, looking at the `user` message "Continue exactly where you left off...".

The `assistant` message (previous turn) ended with: `Temporal Analysis: No observed`

Wait, I am the model. I need to recall what I wrote.

In the first turn, I wrote:

`Temporal Analysis: No observed`

Wait, looking at the very last line of the first assistant response:

`Temporal Analysis: No observed`

Actually, the first assistant response ended with:

`Temporal Analysis: No observed`

Wait, I need to be careful. The text provided in the prompt *under* "user" for the second turn says "Continue exactly where you left off...".

The text *under* "assistant" (the one I need to continue) ends with `Temporal Analysis: No observed`.

Wait, looking at the transcript provided in the prompt:

The last line of the previous assistant message was:

`Temporal Analysis: No observed`

Wait, actually,

threat persistence. No persistently malicious behavior was recorded in the observation window.

The historical log indicates 13 observations, primarily consisting of network classification, geolocation validation, and provider identification signals. Confidence levels for observed signals ranged between 0.30 and 0.90, with recent probes confirming mobile infrastructure characteristics. All signals remained consistent with benign mobile device behavior, and no high-confidence threat indicators were detected in the timeline.

## Recommendations

The IPDebrief tool returned no specific firewall rules for this address, consistent with the low-risk classification. No automated blocking or allowlisting actions were generated by the system. Standard traffic handling is appropriate for mobile carrier infrastructure endpoints.

## Final Assessment

IP 106.219.123.247 is classified as low risk with a score of 25. The address operates as a firewalled mobile connection within the Bharti Airtel network. No immediate blocking or alerting is required based on current threat intelligence. Monitor for changes in risk profile or new threat indicator matches.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionUS-MA
CityBoston
TimezoneAmerica/New_York
Latitude28.41
Longitude77.31

🏒 Ownership & Registration

OrganizationIRT-BHARTI-MO-IN
ASNAS24560
Network NameNoida
CIDR Block106.219.112.0/20
RIRAPNIC
CountryIN
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureMobile
Service PurposeFirewalled / No Services
Network TierUnknown β€” Insufficient routing data to classify
Mobile

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
0%
00
Overall12%33
Coverage: 3/6 dimensions Β· Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-22 13:23:19 UTC
Last Seen2026-07-29 13:13:22 UTC
Profile Built2026-07-29 13:27:09 UTC
Data FreshnessLive
Signal Types17
Total Observations17
πŸ” 17 signal types Β· 17 observations collected
This report is generated from 17+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.