# IP Intelligence Briefing: 117.222.52.247
## Executive Summary
IP 117.222.52.247 is a high-risk (score: 80) address associated with BSNL's Indian national backbone infrastructure. The IP is geolocated to Nagpur, India, and is currently firewalled with no active services. Despite the elevated risk classification, the address shows no active threat indicators, campaigns, or known attacker associations.
## Risk Classification & Reputation
- Overall Risk Score: 80 (High Risk)
- Reputation: High Risk
- Abuse Confidence: Not quantified
- DNSBL Status: Listed on 4 of 8 monitored blacklists
- Operator Score: 0.1304 (Minimal)
- Threat Persistence: 0 days
- Persistent Malicious Activity: False
## Network Ownership & Infrastructure
- ASN: 9829 (IRT-BSNL-IN)
- Organization: BB-Multiplay-General
- CIDR Block: 117.222.0.0/16
- RIR: APNIC
- Registration: BSNL Indian National Internet Backbone
- Network Classification: Firewalled / No Services
## Geolocation Data
- Country: India (IN)
- Region: Maharashtra (MH)
- City: Nagpur
- Coordinates: 21.1161°N, 79.0706°E
- Timezone: Asia/Kolkata
- Geo Validation: Consensus confirmed across multiple sources
## Network Role & Services
- Open Ports: None detected
- TLS Certificate: Not observed
- HTTP Title: Not observed
- Server Banner: Not observed
- Certificate Authority: Not observed
- Service Classification: Network is actively firewalled with no exposed services
## Threat Indicators Assessment
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Known Campaigns: None identified
- Threat Feeds: No active feed associations
- Campaign Likelihood: Not assessed
## Neighborhood Analysis (Subnet: 117.222.52.0/24)
- Total Siblings: 2 active
- Abuse Density: 0%
- Risk Distribution: 0 high-risk, 0 medium-risk, 2 low-risk
- Sibling IPs:
- 117.222.52.177 (Risk Score: 30, Authority Score: 50)
- 117.222.52.206 (Risk Score: 30, Authority Score: 50)
## Historical Signal Activity
- Observation Count: 12 signals recorded
- Data Sufficiency: 83.33% (5 of 6 dimensions covered)
- Recent Activity: Signals observed as recently as 2026-07-30
- Threat Persistence: No persistent malicious behavior detected
- Ownership Changes: None recorded
## Control Plane Data
- BGP Prefix: 117.222.48.0/20
- Route Stability: False
- RPKI State: Not assessed
- IRR Consistency: Not assessed
- Route Changes (30d): 0
- DNSSEC Valid: True
- DNSBL Total Lists: 8 (Listed on 4)
## Recommended Actions for SOC
1. Monitor, Do Not Block: The elevated risk score (80) is primarily due to DNSBL listings. No active threats, campaigns, or attack indicators are present.
2. Passive Monitoring: Enable passive traffic monitoring for this IP to detect any service changes or port openings.
3. Correlate with Subnet: Monitor sibling IPs 117.222.52.177 and 117.222.52.206 which show lower risk scores (30) and may provide contextual threat intelligence.
4. DNSBL Review: Investigate the 4 DNSBL listings to determine if they stem from historical activity, IP sharing issues, or false positives.
5. Geographic Context: BSNL is a major Indian telecommunications provider. Risk may be elevated due to shared infrastructure abuse in the region rather than direct threat activity from this specific address.
## Threat Intelligence Narrative
This IP address represents a BSNL backbone infrastructure endpoint in Nagpur, India. The high-risk classification (80) is driven by DNSBL listings rather than active malicious behavior. The address is currently firewalled with no services exposed, suggesting it may be a management, monitoring, or transit endpoint. No evidence of command-and-control, data exfiltration, or attack activity was found. The subnet environment shows low abuse density with two low-risk siblings. Continued passive monitoring is recommended, but immediate blocking is not warranted absent new threat indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-BSNL-IN |
| ASN | AS9829 |
| Network Name | BB-Multiplay-General |
| CIDR Block | 117.222.0.0/16 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 10:33:13 UTC |
| Last Seen | 2026-07-31 07:30:00 UTC |
| Profile Built | 2026-07-30 20:47:55 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.