# IP Intelligence Briefing: 110.225.227.95/32
## Executive Summary
IP address 110.225.227.95 is a residential broadband endpoint in India assigned to Bharti Airtel Ltd. (AS24560). Current risk assessment indicates Low Risk status with a risk score of 25/100. The IP operates with no open services and is classified as a firewalled residential connection.
## Technical Profile
Geolocation:
- Country: India (IN)
- Region/City: New, Phase III
- Coordinates: 22.0°N, 79.0°E
- Timezone: Asia/Kolkata
Network Infrastructure:
- ASN: AS24560 (Bharti Airtel Ltd.)
- BGP Prefix: 110.225.227.0/24
- Routing Stability: Unstable (isRouteStable: false)
- Operator Score: 0.1304 (Minimal)
- Route Changes (30d): 0
DNS Configuration:
- PTR Hostname: abts-north-dynamic-95.227.225.110.airtelbroadband.in
- Forward Resolution: Confirmed (1 hostname)
- DNSSEC Valid: Yes
- DNSBL Listed: 1 of 8 lists (minimal impact)
- Email Authentication: SPF and DMARC records present
Service Enumeration:
- Open Ports: None detected
- Service Classification: Firewalled / No Services
- TLS Certificate: None
- HTTP Title: None
## Threat Indicators
Current Risk Status:
- Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not assessed
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
Temporal Analysis:
- Threat Persistence Days: 0
- Is Persistently Malicious: No
- Ownership Changes: 0
- Threat Observation Count: 0
## Neighborhood Assessment
Subnet: 110.225.227.0/24
- Total Siblings: 11
- Active Siblings: 3
- Abuse Density: 0 (Clean)
- Subnet Classification: Clean
Neighbor Risk Distribution:
- High Risk: 0
- Medium Risk: 2
- Low Risk: 4
Notable neighbors include 110.225.227.175 (risk 40) and 110.225.227.200 (risk 40), both with authority scores of 50. The target IP maintains a risk score of 25, consistent with residential broadband patterns.
## Historical Observations
Fifteen observations recorded from 2026-07-29:
- ASN attribution: AS24560 Bharti Airtel Ltd. detected across multiple probes
- Geographic signals: Consistent India origin (CH, CH/IN, multiple coordinate sets)
- ICMP Validation: Blocked (unable to validate)
- Port Scans: Multiple scan events observed, no open ports confirmed
- Operator Score: 0.15 (Minimal)
- GeoValidation: Mixed signals with distance variance (6,904.7 km claimed vs. 20.59° coordinates)
## Recommended Actions
Current Status: No immediate action required. The IP presents minimal threat indicators.
Firewall Recommendations:
- Block: Not recommended (low risk)
- Allow with Monitoring: Acceptable if network policy permits residential IP ranges
- Rate Limit: Consider if traffic patterns indicate potential abuse
Monitoring Triggers:
- New service openings on this IP
- Risk score escalation above 50
- DNSBL listing increase
- Neighbor subnet abuse density threshold crossing
## Intelligence Assessment
This IP represents a standard residential broadband endpoint from India's major ISP, Bharti Airtel. The absence of open services, combined with consistent low-risk neighbor profiles, indicates typical residential usage patterns. The single DNSBL listing is likely associated with dynamic IP address management practices rather than active malicious behavior. No actionable threats warrant immediate defensive action at this time.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Network Administrator for ABTS DEL |
| ASN | AS24560 |
| Network Name | ABTS-DSL-MOH |
| CIDR Block | 110.225.192.0/18 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | abts-north-dynamic-95.227.225.110.airtelbroadband.in |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | abts-north-dynamic-95.227.225.110.airtelbroadband.in |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 22% | 6 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-21 12:54:29 UTC |
| Last Seen | 2026-07-29 08:15:19 UTC |
| Profile Built | 2026-07-29 08:24:32 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 24 |
Full dossier details are available via our API.