# INTELLIGENCE BRIEFING: 116.75.218.103
Classification: Moderate Risk - Residential Infrastructure
Date: 2026-06-22
Analyst: IPDebrief Intelligence Team
## EXECUTIVE SUMMARY
IP address 116.75.218.103 is a residential infrastructure endpoint operated by HATHWAY CABLE AND DATACOM LIMITED (ASN 17488) in Delhi, India. The address carries a risk score of 55 (Moderate Risk) with no active threat indicators. The IP exhibits residential network characteristics with standard service ports open. No evidence of persistent malicious behavior or known campaign participation detected.
## RISK PROFILE
| Metric | Value | Assessment |
|---|---|---|
| **Risk Score** | 55 | Moderate Risk |
| **Operator Score** | 0.1304 | Minimal |
| **Abuse Confidence** | N/A | Not Calculated |
| **Blacklist Count** | 3 of 8 | Listed |
| **Stability** | Route Unstable | Variable |
## NETWORK CLASSIFICATION
- Provider Score: 0 (ISP/Provider)
- Authority Score: 0 (Not authoritative)
- Infrastructure Type: Residential
- Connection Type: Residential
- Service Purpose: Multi-Service Host
- Open Ports: 22/tcp (SSH), 8443/tcp (HTTPS-alt)
- DNS Classification: hathway.com domain with valid PTR record (218.75.116.103.hathway.com)
## THREAT INDICATORS
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Known Campaigns: None
- Threat Feeds: No active indicators
- DNSBL Status: Listed on 3 of 8 total lists
## GEOGRAPHIC CONTEXT
- Country: India (IN)
- Region: National Capital Territory of Delhi
- City: Delhi
- ASN Origin: 116.75.218.0/24 (17488)
- Geographic Consensus: True (1 source)
## OBSERVATION HISTORY
Total observations: 23
- Recent Activity: Multiple observations from June 2026
- Email Authentication: hathway.com SPF and DMARC records present and validated
- Operator Score Trend: Consistent minimal operator score (0.1304)
- Threat Persistence: 0 days (not persistently malicious)
- Ownership Changes: 0 (stable ownership)
## RELATIONSHIP GRAPH
- Total Relationships: 35
- Primary Associations: HATHWAY-NET network infrastructure
- Network Classification: Residential residential infrastructure cluster
- Cross-Reference: No correlated threat entities identified
## NEIGHBORHOOD ANALYSIS
- Subnet: 116.75.218.0/24
- Abuse Density: 0 (Clean)
- Classification: Mostly Clean
- Risk Distribution: High: 0, Medium: 0, Low: 0
- Active Siblings: 1 (threat sibling count: 1)
## RECOMMENDED ACTIONS
Based on the moderate risk profile and residential classification:
1. Monitor: Maintain ongoing monitoring due to DNSBL listings and unstable routing
2. Allow with Scrutiny: Standard residential traffic patterns expected; no blocking required
3. Geo-Fencing: Consider geographic filtering if business policy requires
4. Threat Intelligence: No immediate action required; no active threat indicators
## CONCLUSION
The IP address 116.75.218.103 represents legitimate residential infrastructure from HATHWAY's Delhi network. The moderate risk score reflects the residential nature of the address rather than malicious activity. No evidence of abuse, campaign participation, or persistent threat behavior detected. Routine monitoring recommended; no immediate defensive action required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | HATHWAY CABLE AND DATACOM LIMITED |
| ASN | AS17488 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 218.75.116.103.hathway.com |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 218.75.116.103.hathway.com |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Multi-Service Host |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| 8443 | https-alt | tcp | โ |
| Closed Ports | 25, 80, 443, 3389, 8080 (2 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 24% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 20% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:33 UTC |
| Last Seen | 2026-06-22 10:20:59 UTC |
| Profile Built | 2026-06-22 10:27:33 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.