# IP Intelligence Briefing: 110.224.168.161/32
Classification: Moderate Risk
Analysis Date: Current
Risk Score: 40/100
## Executive Summary
IP address 110.224.168.161 is a mobile-originated address assigned to Bharti Airtel mobile infrastructure under organization Rahul Jain (ASN 45609, APNIC). The IP presents moderate risk due to DNSBL listings and route stability anomalies. No active services or open ports detected. Recommended for monitoring and potential blocking.
## Ownership and Registration
- Organization: Rahul Jain
- Netname: BHARTI-MO-IN
- ASN: 45609
- RIR: APNIC
- CIDR Block: 110.224.0.0/14
- Abuse Contact: ip.misuse@airtel.com (via RDAP)
- Mobile Carrier: Airtel (Bharti Airtel Ltd.)
- Connection Type: Mobile (LTE/5G, MCC: 404, MNC: 10)
## Technical Profile
- Geolocation: Atlanta, US (reported); India/Gurgaon (historical data)
- Network Role: Firewalled / No Services
- Open Ports: None detected
- DNS Resolution: Forward confirmed: No
- PTR Hostnames: None
- Email Reputation: No SPF/DMARC records
## Threat Indicators
- DNSBL Listings: 2 of 8 total lists
- Known Attacker: No
- Spam Source: No
- Tor Exit: No
- Vulnerability Scans: Not observed
- Campaign Correlation: No correlated IPs detected
- Threat Persistence: 0 days (not persistently malicious)
## Temporal Analysis
- Observation Count: 12 signals observed
- Recent Activity: Active observations as of July 30, 2026
- Ownership Changes: 0
- Route Stability: Not stable (route changes: 0 in 30 days)
## Network Neighborhood
- Subnet: 110.224.168.161/24
- Siblings: 0 neighbors identified
- Abuse Density: 0
- Risk Distribution: No high/medium/low risk neighbors detected
## Relationships
- Network Association: BHARTI-MO-IN (same network)
- No additional relationships: No related organizations, hostnames, or certificates identified
## Recommended Actions
Based on risk assessment, the following firewall rules are recommended:
iptables:
```
iptables -A INPUT -s 110.224.168.161 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 110.224.168.161 drop
```
nginx:
```
deny 110.224.168.161;
```
pfSense:
```
110.224.168.161/32
```
Cloudflare WAF:
```json
{
"description": "Block 110.224.168.161 β IPDebrief risk score 40",
"action": "block",
"filter": {
"expression": "ip.src eq 110.224.168.161"
}
}
```
AWS WAF:
```json
{
"Addresses": ["110.224.168.161/32"],
"Description": "IPDebrief risk 40"
}
```
## Intelligence Assessment
This IP represents a mobile infrastructure endpoint with moderate risk characteristics. The primary concerns are DNSBL listings and route stability issues. The mobile carrier association (Airtel) suggests the traffic may originate from mobile devices or mobile broadband connections. No evidence of active malicious campaigns or persistent threat behavior. Monitor for changes in threat indicators, particularly if DNSBL listings increase or new threat indicators emerge.
Priority: Medium
Action: Block at perimeter, monitor for pattern changes
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Rahul Jain |
| ASN | AS45609 |
| Network Name | BHARTI-MO-IN |
| CIDR Block | 110.224.0.0/14 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 8% | 2 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-25 14:52:18 UTC |
| Last Seen | 2026-07-30 03:54:21 UTC |
| Profile Built | 2026-07-30 04:02:05 UTC |
| Data Freshness | Live |
| Signal Types | 13 |
| Total Observations | 13 |
Full dossier details are available via our API.