# IP Intelligence Briefing: 106.219.167.157/32
Classification: Low Risk | Risk Score: 0 | Status: Clean
## Executive Summary
IP address 106.219.167.157 is a mobile carrier IP assigned to Bharti Airtel (ASN 24560) within the NOIDA-DELHI-NCR network block (106.219.160.0/20). The IP shows no active threat indicators, no blacklist listings, and zero observed threat activity. Current risk profile indicates no immediate defensive action required, though contextual awareness of the mobile carrier origin is recommended.
## Ownership and Network Context
- ASN: 24560 (IRT-BHARTI-MO-IN)
- Organization: Bharti Airtel Ltd.
- Network Block: 106.219.160.0/20
- Registration Authority: APNIC (APNIC RIR)
- Abuse Contact: ip.misuse@airtel.com
## Geolocation Analysis
- Primary Location: India (Gurgaon, postal code 16 Udhyog Vihar)
- Secondary Location: US (Newark, NJ) β appears as consensus source
- Timezone: America/New_York
- Geographic Consensus: True
- Geographic Plausibility: False (notable flag for further validation)
## Mobile Carrier Classification
- Carrier: Airtel (Bharti Airtel Ltd.)
- MCC/MNC: 404/10
- Technology: LTE/5G
- Service Purpose: Firewalled / No Services
- Open Ports: None detected
## Threat Intelligence Assessment
| Indicator | Status |
|---|---|
| Blacklist Count | 0 |
| DNSBL Listed | 0 |
| Known Attacker | No |
| Spam Source | No |
| Tor Exit Node | No |
| Abuse Confidence Score | N/A |
| Threat Persistence | 0 days |
## Neighborhood Analysis (106.219.167.0/24)
- Subnet Classification: Clean
- Abuse Density: 0%
- Total Siblings: 8 IPs
- Active Siblings: 3 IPs
- Threat Siblings: 0
Notable Neighbor Risk Scores:
- 106.219.167.114: Risk 40 (highest in subnet)
- 106.219.167.28, .124, .127: Risk 25
- 106.219.167.78: Risk 15
- 106.219.167.113: Risk 0
- 106.219.167.130: No data
## Historical Trend Analysis
Twelve signal observations tracked over recent period. Key trends:
- Classification: Consistently "clean"
- Abuse density: Stable at 0
- Ownership changes: 0
- Threat observation count: 0
- No evidence of persistently malicious activity
## Network Services and DNS
- DNS Records: No forward resolution confirmed
- PTR Hostnames: None
- Hosted Domains: 0
- Open Services: None (firewalled)
- TLS/SSL: No certificates detected
- HTTP Services: No active HTTP endpoints
## Recommended Security Actions
Current Risk Level: 0/100
- No immediate firewall rules required
- No WAF rules recommended
- No blocking action advised
Monitoring Recommendations:
1. Flag as mobile carrier traffic for traffic pattern analysis
2. Monitor for service activation on this IP
3. Track geographic consistency (India vs US location discrepancy)
4. Review neighbor IP 106.219.167.114 (risk score 40) for contextual threat assessment
## Intelligence Conclusion
IP 106.219.167.157 represents a Bharti Airtel mobile network address with no current threat indicators. The IP is geographically associated with India (Gurgaon) but shows US geolocation data requiring validation. The subnet shows minimal abuse density, though one neighbor IP (106.219.167.114) shows elevated risk and warrants separate investigation. No immediate defensive actions are required, but maintain contextual awareness of mobile carrier traffic patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | IRT-BHARTI-MO-IN |
| ASN | AS24560 |
| Network Name | NOIDA-DELHI-NCR |
| CIDR Block | 106.219.160.0/20 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-22 13:23:19 UTC |
| Last Seen | 2026-07-29 13:13:42 UTC |
| Profile Built | 2026-07-29 13:24:23 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 15 |
Full dossier details are available via our API.