# IP INTELLIGENCE BRIEFING: 117.231.166.254
Classification: Moderate Risk | Date: 2026-07-30
Status: No Active Threat Indicators | Action: Monitor/Block (Risk Score 50)
---
## Executive Summary
IP address 117.231.166.254 presents a moderate risk profile (50/100) with no active threat indicators. The address is geolocated to Kurumpilavu, Kerala, India, and is associated with AS9829 (National Internet Backbone). No open services or active attack patterns observed. Recommended for defensive blocking due to DNSBL listings.
---
## Technical Profile
Geolocation:
- Country: India (IN)
- Region: Kerala
- City: Kurumpilavu
- Coordinates: 10.41°N, 76.17°E
Network Classification:
- ASN: AS9829 (National Internet Backbone)
- BGP Prefix: 117.231.160.0/20
- Route Stability: Unstable
- DNSBL Listings: 2 of 8 (25%)
- Operator Score: 0.1304 (Minimal)
Service Status:
- Open Ports: None
- TLS Certificates: None
- HTTP Services: None
- Classification: Firewalled / No Services
Ownership & Attribution:
- Organization: Not available
- Abuse Contact: Not available
- Registration Date: Not available
---
## Threat Analysis
Current Risk Indicators:
- Risk Score: 50 (Moderate)
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Proxy/Vpn: No
- Mobile/Residential: No
- Cloud/CDN/Hosting: No
DNS Reputation:
- Forward Resolution: None
- Hosted Domains: 0
- Email Authentication: SPF/DMARC: Not configured
- DNSBL Listed: Yes (2 lists)
---
## Historical Observations
Observation Count: 9 signals recorded
Most Recent: 2026-07-30 20:36:57 UTC
Timeline:
- 2026-07-30 20:35:54: Geolocation confirmed (Kerala, India)
- 2026-07-30 20:36:32: ASN identified as AS9829
- 2026-07-30 20:36:57: Operator score evaluated (Minimal)
- 2026-07-30 20:36:57: Network classification assessed
- 2026-07-30 20:37:41: Network role confirmed (Firewalled)
Threat Persistence: 0 days
Ownership Changes: 0
Campaign Correlation: None
---
## Relationship & Neighborhood Analysis
Direct Relationships: None detected (0)
Subnet Analysis: 117.231.166.0/24
- Total Siblings: 0
- Active Siblings: 0
- Threat Siblings: 0
- Abuse Density: 0%
Neighboring IPs: None identified in immediate /24 range
---
## Recommended Actions
Firewall Rules (Block Recommendation):
```bash
# iptables
iptables -A INPUT -s 117.231.166.254 -j DROP
# nftables
nft add rule inet filter input ip saddr 117.231.166.254 drop
# nginx
deny 117.231.166.254;
# pfSense
117.231.166.254/32
# Cloudflare WAF
ip.src eq 117.231.166.254
# AWS WAF
Addresses: 117.231.166.254/32
```
Threat Intelligence Notes:
- Probabilistic block recommendation based on risk score 50
- No observed malicious behavior in observation history
- Route stability issues may indicate network churn
- DNSBL presence warrants defensive treatment
- No network relationships to investigate further
---
Analyst Notes: This IP exhibits standard backbone infrastructure behavior with minimal threat indicators. The primary concern is DNSBL listing. Monitor for service emergence or relationship development. No immediate threat action required beyond defensive blocking if risk tolerance permits.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-BSNL-IN |
| ASN | AS9829 |
| Network Name | BSNL-GSM-SouthZone |
| CIDR Block | 117.231.128.0/18 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 10:33:13 UTC |
| Last Seen | 2026-07-31 05:27:35 UTC |
| Profile Built | 2026-07-30 20:47:55 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.