IP Intelligence Briefing: 115.99.148.189
Date: 2026-06-08
---
**1. Risk Profile**
- Overall Risk Score: 70 (High Risk)
- Ownership: Registered to Hathway Cable and Datacom Limited (AS17488) in India.
- Geolocation: Residential network in Bengaluru, Karnataka, India (latitude 12.98, longitude 77.59).
- Threat Indicators:
- Listed in 4/8 DNSBLs (high-risk domains).
- No direct malware, phishing, or exploit indicators.
- BGP data shows stable routing (no recent route changes).
---
**2. Network Behavior**
- Network Type: Residential / Firewalled (no open services detected).
- Subnet: Part of 115.96.0.0/14 (Hathwayโs CIDR block).
- Neighbor Analysis:
- No active neighbors in the /24 subnet.
- Subnet abuse density: 0% (no malicious activity detected in sibling IPs).
---
**3. DNS and Hosting**
- PTR Records: Resolves to 148.99.115.189.hathway.com (Hathwayโs domain).
- Email Security: SPF and DMARC records detected, but no email-related threats.
- Hosting: No hosted domains or services identified.
---
**4. Historical Observations**
- Recent Activity (2026-06-08):
- DNSBL listings (4/8 lists) suggest potential abuse.
- Residential classification confirmed via geolocation and BGP.
- No persistent malicious activity or campaign ties.
---
**5. Relationships**
- Linked Entities:
- Hathway-NET (AS17488) โ same network provider.
- DNS Hostname: 148.99.115.189.hathway.com (no malicious domains).
---
**6. Recommendations**
- Monitor: Track DNSBL listings and check if Hathwayโs network has broader abuse patterns.
- Block: Consider blocking the IP if further analysis confirms malicious intent (e.g., compromised residential device).
- Investigate: Verify DNS associations for legitimacy; ensure no phishing or spoofing activity.
Conclusion: The IP is part of a residential network with no direct malicious activity but shows DNSBL listings. Further monitoring is advised to confirm legitimacy.
---
Source: IPDebrief Threat Intelligence Platform
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | HATHWAY CABLE AND DATACOM LIMITED |
| ASN | AS17488 |
| Network Name | HATHWAY-NET |
| CIDR Block | 115.96.0.0/14 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 148.99.115.189.hathway.com |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 148.99.115.189.hathway.com |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 2/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 13% | 1 | 1 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 35% | 2 | 3 |
| reputation | 0% | 0 | 0 |
| geolocation | 13% | 1 | 1 |
| Overall | 15% | 6 | 7 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 09:23:08 UTC |
| Last Seen | 2026-06-08 12:25:42 UTC |
| Profile Built | 2026-06-08 13:24:40 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.