# IP Intelligence Briefing: 117.217.212.252
## Executive Summary
IP address 117.217.212.252 presents a MODERATE RISK profile (Risk Score: 40) associated with BSNL's broadband infrastructure network in India. The IP is classified as "Firewalled / No Services" with no active open ports or running services detected.
## Ownership and Network Context
- Organization: IRT-BSNL-IN (BB-Multiplay-General)
- ASN: 9829
- Network Block: 117.216.0.0/15
- Geolocation: India (IN), Kerala region, Kara city area
- Registration: APNIC RIR registry
## Risk Assessment
- Overall Risk Score: 40/100 (Moderate)
- DNSBL Listings: 2 out of 8 total lists (dnsblListedCount: 2)
- Abuse Density: Subnet classified as "mostly_clean" with minimal inherited risk
- Network Classification: Provider infrastructure, no CDN/Cloud/VPN/proxy indicators
## Threat Indicators
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Matches: None detected (certMatches: 0, bannerMatches: 0)
- Blacklist Count: 0 (threat section)
- Threat Persistence: Not persistently malicious
## Service Footprint
- Open Ports: None detected
- TLS Certificate: None
- HTTP Response: None
- DNS Resolution: No forward resolution confirmed
- Hosted Domains: 0
## Historical Observations
Analysis of 17 signal observations indicates:
- Threat observation count: 1
- No persistent malicious behavior detected
- Recent activity (as of 2026-06-17) shows standard broadband network classification
- Geographic data: Inferred location in India with 1500km accuracy radius
## Neighborhood Analysis
- Subnet: 117.217.212.0/24
- Abuse Density: 0
- Active Siblings: 1
- Threat Siblings: 1
- Risk Distribution: Low risk profile for neighboring IPs
## Recommended Actions
Based on the risk profile, the following mitigation controls are recommended:
Firewall Rules:
- iptables: `iptables -A INPUT -s 117.217.212.252 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 117.217.212.252 drop`
- nginx: `deny 117.217.212.252;`
- pfSense: `117.217.212.252/32`
Cloud WAF:
- Cloudflare WAF: Block with expression `ip.src eq 117.217.212.252`
- AWS WAF: Add 117.217.212.252/32 to blocklist
## Analyst Notes
This IP belongs to BSNL's broadband multiplay infrastructure and shows moderate risk indicators primarily from DNSBL listings. While no active services or open ports are detected, the presence on multiple blacklist feeds warrants defensive blocking. The subnet shows low abuse density, suggesting this may be an isolated reputation issue rather than coordinated malicious activity.
Priority: MEDIUM - Implement blocking rules and monitor for pattern changes.
---
*Report generated: IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-BSNL-IN |
| ASN | AS9829 |
| Network Name | BB-Multiplay-General |
| CIDR Block | 117.216.0.0/15 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:33 UTC |
| Last Seen | 2026-06-22 10:34:46 UTC |
| Profile Built | 2026-06-22 10:39:43 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 19 |
Full dossier details are available via our API.