# IP INTELLIGENCE BRIEFING
Target: 117.205.82.238/32
Classification: LOW RISK / MONITOR
Report Date: 2026-07-29
---
## Executive Summary
IP 117.205.82.238 presents a low-risk profile with a reputation score of 30. The address is geolocated to Chicago, Illinois, and associated with ASN 9829. No active threat indicators, malicious campaigns, or infrastructure services were observed. The IP appears to be a residential or consumer-facing address that is currently firewalled with no open ports.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 30 (Low Risk) |
| **Provider Score** | 0 |
| **Authority Score** | 0 |
| **Stability Score** | 0 |
| **Geolocation** | US, Illinois, Chicago |
| **ASN** | 9829 |
| **Network Role** | Firewalled / No Services |
| **DNS Resolution** | None detected |
| **Open Ports** | None |
| **Blacklist Status** | Listed on 2 of 8 DNSBL feeds |
---
## Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Active Campaigns: None identified
- DNSBL Listings: 2 lists (medium severity)
- Threat Persistence: 0 days
- Honeypot Hits: 0
- WAF Violations: 0
---
## Neighborhood Analysis
The /24 subnet (117.205.82.0/24) shows minimal risk concentration:
- Abuse Density: 0
- Total Siblings: 1
- Threat Siblings: 0
- Neighbor IP: 117.205.82.17 (Risk Score: 15)
The subnet demonstrates low abuse activity with only one neighboring IP exhibiting low-risk characteristics.
---
## Observational History
Nine observations recorded as of 2026-07-29:
- DNSSEC Validation: Confirmed valid (confidence 0.90)
- Operator Score: 0.1304 (Minimal operator activity)
- Blacklist Detection: 2 listings identified with medium severity (confidence 0.85)
- Network Scan Data: Multiple port scan observations recorded
- Signal Confidence Range: 0.12โ0.90 across observations
The IP exhibits persistent low-level signals without escalation to malicious activity.
---
## Relationship Graph
No relationships identified to:
- Associated subnets
- Hostnames or domains
- Organizations
- Certificates
- Correlated malicious IPs
---
## Recommended Actions
Firewall Rule: No immediate blocking recommended. Monitor for changes in risk score or new threat indicators.
Monitoring Priority: LOW
- Track blacklist status changes
- Monitor for new open ports or service changes
- Watch for correlation with emerging threat campaigns
Additional Context:
- Traceroute indicates 30 hops with 12 timeouts, traversing Comcast and Cogent networks
- BGP prefix: 117.205.80.0/20
- Route stability: Unstable
- RPKI state: Not verified
- DNSSEC: Valid
---
Analysis Notes: This IP represents a benign consumer address with minor blacklist presence. The absence of open ports, services, or active threat indicators suggests legitimate use. The blacklist listings may be due to historical activity or false positives. Continue standard monitoring procedures without elevated alerting.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-BSNL-IN |
| ASN | AS9829 |
| Network Name | BB-Multiplay |
| CIDR Block | 117.205.128.0/17 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-21 19:02:36 UTC |
| Last Seen | 2026-07-29 10:02:49 UTC |
| Profile Built | 2026-07-29 10:12:43 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.