# IP Intelligence Briefing: 106.221.255.255/32
Date: 2026-07-29
Classification: Low Risk
Analyst: IPDebrief Intelligence Team
---
## Executive Summary
IP address 106.221.255.255 presents a low-risk threat profile. The address is associated with mobile carrier infrastructure (Bharti Airtel Ltd., ASN 45609) and shows no active malicious indicators. No immediate blocking or filtering actions are recommended based on current intelligence.
---
## Ownership and Network Classification
- Organization: Rahul Jain (BHARTI-MO-IN)
- ASN: 45609
- RIR: APNIC
- CIDR Block: 106.192.0.0/11
- Abuse Contact: ip.misuse@airtel.com
- Network Role: Mobile carrier infrastructure (Airtel, MCC 404, MNC 10)
- Connection Type: LTE/5G mobile network
---
## Geolocation Assessment
Primary Assignment: US (Newark, NJ)
Historical Assignment: India (Gurgaon, IN)
*Note: Geolocation data shows regional discrepancies between current and historical records. This is consistent with mobile carrier IP routing patterns where address space may be allocated in one region but routed through another. The APNIC registration indicates legitimate regional allocation.*
---
## Threat Intelligence
- Risk Score: 0/100
- Abuse Confidence: Not applicable (no abuse signals)
- Threat Indicators: None detected
- Blacklist Status: Not listed on any feeds
- Known Campaigns: None correlated
- Tor/Proxy Status: Not a Tor exit node, proxy, or CDN
---
## Network Behavior and Services
- Open Ports: None detected
- DNS Resolution: No forward resolution, no PTR records
- HTTP/HTTPS: No services running
- Status: Firewalled / No services accessible
---
## Control Plane Analysis
- BGP Prefix: 106.221.252.0/22
- Operator Score: 0.1304 (Minimal)
- Route Stability: Not currently stable
- DNSSEC: Valid
- ISP Classification: Mobile carrier network
---
## Neighborhood Analysis (106.221.255.0/24)
- Abuse Density: 0%
- Active Siblings: 0
- Threat Siblings: 0
- Risk Distribution: No high/medium risk neighbors
- Classification: Clean subnet
---
## Historical Observation (Last 24 Hours)
11 observations recorded:
- Ownership data consistent (Rahul Jain, BHARTI-MO-IN)
- Abuse contact maintained (ip.misuse@airtel.com)
- No ownership changes detected
- No threat persistence observed
- Confidence levels range from 0.12 to 0.95
---
## Intelligence Assessment
The IP address represents standard mobile carrier infrastructure with no malicious activity. The geolocation discrepancy between US and India assignments is typical for mobile networks with complex routing and regional allocation. The absence of open services and the firewalled state further reduce concern.
Threat Level: Low
Action Required: None
Monitoring Recommendation: Standard monitoring only; no special attention needed.
---
## Recommended Actions
No immediate actions required. The IP presents no actionable threat indicators. If traffic from this address is observed in security monitoring, it should be treated as legitimate mobile carrier traffic unless accompanied by other suspicious indicators.
---
Report Generated: IPDebrief Intelligence Platform
Data Sources: IP reputation databases, geolocation services, threat intelligence feeds, network classification data
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Rahul Jain |
| ASN | AS45609 |
| Network Name | BHARTI-MO-IN |
| CIDR Block | 106.192.0.0/11 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 13:23:19 UTC |
| Last Seen | 2026-07-29 13:13:52 UTC |
| Profile Built | 2026-07-29 13:24:23 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.