# IP Intelligence Briefing: 117.222.139.89
Classification: High Risk
Date of Analysis: 2026-07-30
Analyst: IPDebrief SOC Intelligence Team
---
## Executive Summary
IP address 117.222.139.89 was identified as a high-risk endpoint during automated scanning operations. The address demonstrates a risk score of 80/100, indicating elevated threat potential despite limited observable malicious activity. The IP belongs to BSNL's multi-play broadband infrastructure and is geolocated to Kanchipuram, Tamil Nadu, India.
---
## Ownership and Geolocation
The IP address is registered under ASN 9829 (IRT-BSNL-IN), operating within the BB-Multiplay-General network block (117.222.0.0/16). Geolocation data indicates placement in Kanchipuram, Tamil Nadu (IN), with a consensus accuracy radius of 1500km. Multiple geolocation sources confirm this placement.
Network Classification:
- Infrastructure Type: ISP/Multi-play broadband
- Connection Type: Residential/business broadband
- Cloud/VPN/Proxy: No
- Mobile Carrier: No
---
## Threat Assessment
Current Risk Profile:
- Risk Score: 80 (High)
- Provider Score: 0
- Authority Score: 0
- Operator Score: 0.1304 (Minimal)
Threat Indicators:
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Active Threat Feeds: None detected
Control Plane Analysis:
- DNSBL Listings: 4 of 8 total lists
- Route Stability: Unstable
- RPKI State: Not verified
- IRR Consistency: Not verified
---
## Network Behavior and Services
Service Enumeration:
- Open Ports: None detected
- HTTP/HTTPS: No services detected
- TLS Certificates: None
- Server Banner: No banner detected
The IP appears firewalled with no active services exposed. This configuration suggests either a dormant endpoint, residential connection, or intentionally hardened infrastructure.
---
## Neighborhood Analysis
Subnet: 117.222.139.89/24
- Abuse Density: 0.0
- Classification: Clean
- Active Siblings: 0
- Threat Siblings: 0
- Total Siblings: 1
The /24 subnet demonstrates minimal abuse activity, with no neighboring IPs flagged as threats. This indicates the high-risk score for 117.222.139.89 may stem from historical data, DNSBL listings, or control plane anomalies rather than current malicious activity.
---
## Historical Observations
Fifteen signal observations were recorded, with the most recent activity occurring on 2026-07-30. Historical patterns show:
- Multiple scanning events with moderate confidence levels (0.30-0.85)
- No persistent malicious behavior detected
- No ownership changes recorded
- Threat persistence days: 0
The observation count suggests automated scanning interest rather than sustained adversarial activity.
---
## Relationship Graph
Five relationship entries were identified, all pointing to the parent network "BB-Multiplay-General." No external entity associations (hostnames, organizations, certificates) were discovered.
---
## Recommended Actions
For SOC Analysts:
1. Monitor: The high risk score warrants continued monitoring despite clean neighborhood metrics
2. DNSBL Review: Investigate the 4 DNSBL listings for 117.222.139.89 to understand listing rationale
3. Baseline: Establish baseline behavior given the firewalled/no-service state
4. Correlation: Cross-reference with threat intelligence feeds for BSNL network-wide patterns
Firewall/Blocking Decision:
- Block if: IP appears in active threat feeds or shows malicious behavior
- Monitor if: No confirmed malicious activity; risk score may be legacy
- Allow if: Legitimate inbound traffic confirmed and no threat indicators present
---
## Conclusion
IP 117.222.139.89 presents a high-risk profile primarily driven by DNSBL listings and control plane anomalies rather than active threat indicators. The clean neighborhood classification and lack of observable services suggest this may be a dormant or residential endpoint. Continued monitoring is recommended to track risk score evolution, particularly given the discrepancy between the 80/100 risk score and minimal current threat observations.
Priority: Medium
Action Required: Monitor DNSBL listings and threat feed correlations
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-BSNL-IN |
| ASN | AS9829 |
| Network Name | BB-Multiplay-General |
| CIDR Block | 117.222.0.0/16 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 26% | 7 | 8 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 10:33:13 UTC |
| Last Seen | 2026-07-31 07:30:00 UTC |
| Profile Built | 2026-07-30 20:47:55 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.