IP Intelligence Briefing: 117.250.107.180
*Generated via IPDebrief Analysis*
---
**1. Core Profile**
- Risk Score: 80 (High Risk)
- Ownership: Registered to BSNLNET (AS9829, APNIC) โ Indian telecom provider.
- Geolocation: Jharkhand, India (city: Dhanbad, 1500km accuracy radius).
- Network Role: Multi-service host (HTTP/SSH services, no CDN/VPN/Cloud flags).
- Threat Indicators: No malicious activity observed; no known campaigns, blacklists, or abuse confidence scores.
---
**2. Observations**
- Latest Activity:
- HTTP service (port 80) with 200 status code, no malicious banners.
- SSH service (port 22) using Dropbear, with a specific banner string.
- Historical Data:
- 21 observations since June 2026, showing consistent HTTP/SSH traffic.
- No spikes in threat signals or DNS anomalies.
- Control Plane:
- BGP prefix: `117.250.96.0/20` (route stability: unstable).
- DNSSEC valid, but 5/8 DNSBL lists flagged the IP (low confidence).
---
**3. Relationships**
- Network Connections:
- Linked to BSNLNET (same network).
- No direct relationships to other IPs, organizations, or certificates.
- Subnet: Part of `117.250.107.180/24`, but no neighboring IPs detected.
---
**4. Neighborhood Analysis**
- Subnet Abuse Density: 1 (mostly clean, minimal inherited risk).
- Neighbors: No active sibling IPs in the /24 subnet.
---
**5. Actionable Insights**
- Monitor SSH Service: The Dropbear SSH banner may indicate a specific configuration or potential misconfiguration.
- Verify DNSSEC: Despite DNSSEC validity, the IP is listed on 5/8 DNSBLs. Investigate if this is a false positive or misconfigured resolver.
- Network Segmentation: The lack of neighboring IPs in the subnet may suggest isolated infrastructure or potential misclassification.
- Threat Context: While the IP shows no direct malicious activity, its high risk score and BSNL ownership warrant further investigation into potential misuse of enterprise resources.
---
Conclusion: The IP is registered to a legitimate telecom provider but exhibits high risk due to network instability and DNSBL listings. No immediate threat detected, but ongoing monitoring for unusual traffic patterns is recommended.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-BSNL-IN |
| ASN | AS9829 |
| Network Name | BSNLNET |
| CIDR Block | 117.192.0.0/10 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static.ill.117.250.107.180.bsnl.co.in |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | static.ill.117.250.107.180.bsnl.co.in |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Multi-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-dropbear_2013.62 ? ?_???n5o~?{?$?curve25519-sha256@libssh.org,ecdh-sha2-nistp521,ecdh-sha2- |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 4 |
| ownership | 24% | 2 | 3 |
| reputation | 21% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 23% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:33 UTC |
| Last Seen | 2026-06-24 01:22:12 UTC |
| Profile Built | 2026-06-22 10:46:19 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.