# IP Intelligence Briefing: 117.195.239.101/32
Date: 2026-07-30
Risk Level: Moderate Risk (55/100)
Classification: Residential/ISP Infrastructure
## Executive Summary
IP address 117.195.239.101 is registered to BSNL (Indian Railways Telecommunications Limited) under ASN 9829 (IRT-BSNL-IN) within the BB-Multiplay CIDR block (117.194.0.0/15). The IP is geolocated to Katihar, Bihar, India. While the IP shows elevated risk scoring (55/100), no active threat indicators, known campaigns, or malicious behavior patterns were detected. The network segment exhibits low abuse density with no neighboring IPs showing confirmed malicious activity.
## Technical Profile
Ownership:
- ASN: 9829
- Organization: IRT-BSNL-IN
- CIDR Block: 117.194.0.0/15
- RIR: APNIC
- Abuse Contact: Available via RDAP
Geolocation:
- Country: India (IN)
- Region: Bihar
- City: Katihar
- Location Confidence: 1500km radius
- Geo Sources: 1 (Consensus: True)
Network Classification:
- Service Purpose: Firewalled / No Services
- Infrastructure Type: No CDN, Cloud, or Hosting detected
- Connection Type: Not identified as proxy, Tor, VPN, or mobile carrier
## Threat Assessment
Current Risk Indicators:
- Risk Score: 55/100 (Moderate)
- Known Attacks: None
- Spam Source: No
- Tor Exit Node: No
- Blacklist Status: 0 entries
- DNSBL Listings: 3/8 total lists
Behavioral Analysis:
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: 0
- Threat Persistence: None (0 days)
- Persistently Malicious: False
DNS Analysis:
- PTR Resolution: None detected
- Forward Resolution: 0 records
- Hosted Domains: 0
- Email Authentication: No SPF or DMARC records
- DNSSEC: Valid
## Service Exposure
Active Services:
- Open Ports: None detected
- TLS Certificate: None
- HTTP Banner: None
- Server Type: Not identified
Control Plane:
- BGP Prefix: 117.195.224.0/20
- Route Stability: False
- RPKI State: Not verified
- Route Changes (30d): 0
## Historical Observation (16 Signals)
The IP has been observed in 16 intelligence signals. Recent observations (2026-07-30) show:
- Ownership verification: BSNL infrastructure confirmed
- Network classification: Residential/ISP infrastructure
- No service changes detected
- No threat behavior observed
- Ownership stability: No changes recorded
## Network Neighborhood Analysis
Subnet: 117.195.239.101/24
- Total Siblings: 1
- Active Siblings: 0
- Abuse Density: 0
- Threat Siblings: 0
Related IPs:
- 117.195.239.84 (Risk Score: Not determined)
Relationship Graph: 2 relationships identified, all pointing to BB-Multiplay network infrastructure.
## Recommended Actions
Immediate:
- Increase logging verbosity for traffic from this IP
- Review recent activity patterns in security logs
- Monitor for any behavioral changes
Firewall Recommendations:
- iptables: `iptables -A INPUT -s 117.195.239.101 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 117.195.239.101 drop`
- nginx: `deny 117.195.239.101;`
- pfSense: Block 117.195.239.101/32
- Cloudflare WAF: Block with expression `ip.src eq 117.195.239.101`
- AWS WAF: Add to IPSet for blocking
Severity: High (Due to elevated risk score requiring monitoring)
## Intelligence Narrative
The IP 117.195.239.101 presents as a residential/ISP endpoint within BSNL's multi-play infrastructure. The moderate risk score of 55/100 warrants attention but does not indicate confirmed malicious activity. The IP has no open services, no known associations with threat campaigns, and no historical malicious behavior. The absence of open ports suggests the endpoint is either properly secured or inactive. The single DNSBL listing across 8 lists may indicate minor reputation issues but no critical blacklisting.
Recommendation: Monitor rather than immediately block. The IP shows no active threat indicators. Implement enhanced logging and review recent traffic patterns. If this IP appears in security alerts, investigate the context of those alerts before applying blocking rules. The low neighborhood abuse density suggests this is likely an isolated endpoint rather than part of a compromised network segment.
---
*This briefing was generated using IPDebrief threat intelligence tools. All data reflects observations as of 2026-07-30.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-BSNL-IN |
| ASN | AS9829 |
| Network Name | BB-Multiplay |
| CIDR Block | 117.194.0.0/15 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-28 10:06:03 UTC |
| Last Seen | 2026-07-30 16:06:40 UTC |
| Profile Built | 2026-07-30 16:17:27 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 19 |
Full dossier details are available via our API.