# IP Intelligence Briefing: 106.222.216.150
## Executive Summary
IP address 106.222.216.150 is classified as Moderate Risk with a risk score of 50/100. The address belongs to Bharti Airtel's mobile network infrastructure (ASN 24560) and is geolocated to India. Current threat indicators show no active malicious activity, though the IP is listed on 2 DNSBLs out of 8 total checks. Recommended action: Block with contextual awareness.
## Ownership and Network Classification
- ASN: 24560 (IRT-BHARTI-MO-IN)
- Organization: Bhubaneswar (Mobile Network Infrastructure)
- CIDR Block: 106.222.192.0/19
- RIR: APNIC (Asia-Pacific)
- Route Origin: 106.222.216.0/22
- RPKI State: Valid
- Route Changes (30d): 1 (route is not stable)
- Delegation Age: 7,472 days (allocated 2006-02-13)
## Geolocation Data
- Country: India (IN)
- Region: Madhya Pradesh
- City: Bhopal
- Coordinates: 23.2505, 77.4065 (claimed)
- Distance Validation: 6,692 km (ICMP blocked - unable to validate)
- GeoConsensus: True
## Connection and Service Profile
- Mobile Carrier: Airtel (Bharti Airtel Ltd.)
- Connection Type: LTE/5G (Mobile)
- Network Role: Firewalled / No Services
- Open Ports: None detected
- TLS Certificate: None
- HTTP Services: None
- Is Cloud/CDN/VPN/Proxy/Tor: All false
- Is Hosting: False
## Threat Indicators
- Risk Score: 50 (Moderate Risk)
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Blacklist Count: 0 (direct)
- DNSBL Listings: 2/8 lists
- Known Campaigns: None
- Threat Persistence: 0 days (not persistently malicious)
## Neighborhood Analysis
- Subnet: 106.222.216.150/24
- Abuse Density: 0 (clean classification)
- Total Siblings: 2
- Active Siblings: 0
- Threat Siblings: 0
- Neighbor IP: 106.222.216.158 (Risk Score: 0)
The immediate /24 subnet shows no abuse activity, indicating this is an isolated mobile IP rather than part of a compromised subnet.
## Historical Observations (18 signals)
Recent observations (2026-07-30) show:
- Valid RPKI route origin (106.222.216.0/22) via ASN 24560
- Stable mobile network classification
- No changes in network role or threat indicators
- Geolocation data remains consistent
The IP has shown no persistent malicious behavior over the observation period.
## Relationships
All detected relationships link to the "Bhubaneswar" network, confirming the IP's association with Bharti Airtel's mobile infrastructure.
## Recommended Security Actions
Firewall Rules
```bash
# iptables
iptables -A INPUT -s 106.222.216.150 -j DROP
# nftables
nft add rule inet filter input ip saddr 106.222.216.150 drop
# nginx
deny 106.222.216.150;
# pfSense
106.222.216.150/32
# Cloudflare WAF
ip.src eq 106.222.216.150 (action: block)
# AWS WAF
106.222.216.150/32
```
SOC Analyst Guidance
1. Block Decision: The moderate risk score (50) with DNSBL listings warrants blocking, but the lack of active threat indicators suggests this may be a false positive.
2. Context: This is a mobile network IP, not a datacenter or hosting provider. Mobile IPs are common for legitimate users.
3. Monitor: Track for any changes in risk score or new threat indicators.
4. Consider: If blocking is implemented, allow a grace period and monitor for legitimate traffic impacts from mobile users.
## Risk Assessment Summary
| Factor | Assessment |
|---|---|
| Risk Score | 50 (Moderate) |
| Threat Activity | None detected |
| Neighborhood Risk | Clean |
| Historical Behavior | Stable, no persistence |
| Network Type | Mobile (Airtel) |
| Recommendation | Block with monitoring |
---
*Report generated based on IPDebrief intelligence platform data. All conclusions drawn from observed signals and public data sources.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-BHARTI-MO-IN |
| ASN | AS24560 |
| Network Name | Bhubaneswar |
| CIDR Block | 106.222.192.0/19 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 25% | 1 | 1 |
| geolocation | 35% | 2 | 2 |
| Overall | 28% | 8 | 9 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (65%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 16:40:59 UTC |
| Last Seen | 2026-07-31 07:29:46 UTC |
| Profile Built | 2026-07-30 22:20:26 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.