# IP INTELLIGENCE BRIEFING: 117.98.208.217/32
Classification: Moderate Risk | Assessment Date: 2026-07-30
Intel Source: IPDebreak Threat Intelligence Platform
---
## EXECUTIVE SUMMARY
The IP address 117.98.208.217 presents a moderate risk profile (55/100) with characteristics consistent with residential mobile broadband connectivity from India. The IP is associated with Bharti Airtel's mobile network infrastructure and exhibits no persistent malicious activity. While the subnet shows clean abuse density, the elevated risk score warrants enhanced monitoring.
---
## NETWORK ATTRIBUTES
| Attribute | Value |
|---|---|
| **ASN** | 24560 |
| **Organization** | Rashim Kapoor (UPPAL-HYDERABAD-AP) |
| **Country** | India (IN) |
| **Region/City** | Telangana, Mallฤpur |
| **Registration** | APNIC |
| **CIDR Block** | 117.98.192.0/19 |
---
## CONNECTIVITY CLASSIFICATION
- Connection Type: Mobile broadband (LTE/5G via Bharti Airtel)
- Provider Classification: Residential mobile carrier
- Infrastructure Flags: Not a CDN, cloud, proxy, VPN, Tor exit, or hosting service
- Service Status: Firewalling enabled / No services exposed
- Reverse DNS: telemedia-ap-dynamic-217.208.98.117.airtelbroadband.in
- Forward DNS: Single dynamic hostname resolution confirmed
---
## THREAT INDICATORS
- Risk Score: 55/100 (Moderate)
- Abuse Confidence Score: Not applicable
- Blacklist Status: 3 DNSBL listings out of 8 total lists
- Threat Campaigns: None detected
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
Control Plane Analysis:
- Operator Score: 0.1304 (Minimal)
- Route Stability: Unstable (non-MOAS)
- DNSSEC Validation: Valid
- RPKI State: Not applicable
---
## TEMPORAL ANALYSIS
Observation History (17 signals collected):
- Recent subnet classification: Clean (abuse density: 0)
- Geographic consistency: India (confidence: 0.52)
- Mobile network detection: Confirmed
- Threat persistence: 0 days
- Persistent malicious activity: False
- Ownership changes: 0
Assessment: The IP demonstrates stable characteristics without evolving threat patterns. No escalation of malicious behavior observed in observation history.
---
## NETWORK CONTEXT
Subnet Analysis (117.98.208.0/24):
- Abuse Density: 0 (Clean)
- Active Threat Siblings: 0
- Total Subnet Siblings: 1
- Classification: Clean
- Inherited Risk: 0
Relationship Graph:
- Network associations: UPPAL-HYDERABAD-AP (multiple)
- DNS associations: airtelbroadband.in dynamic hostnames (4 entries)
- No cross-network relationships detected
---
## RECOMMENDED ACTIONS
Priority: HIGH โ Risk score (55/100) exceeds normal baseline for residential mobile IPs
Monitoring
- Increase logging verbosity for traffic from this IP
- Review recent activity patterns and connection logs
- Monitor for any changes in behavior or port scanning activity
Mitigation (Recommended by IPDebrief)
- iptables: `iptables -A INPUT -s 117.98.208.217 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 117.98.208.217 drop`
- nginx: `deny 117.98.208.217;`
- pfSense: Block 117.98.208.217/32
- Cloudflare WAF: Block IP (risk score 55)
- AWS WAF: Add 117.98.208.217/32 to IP set
Note: Recommendations are probabilistic. Combine with additional signals before implementing blocking measures.
---
## INTELLIGENCE ASSESSMENT
The IP address 117.98.208.217 represents a residential mobile broadband endpoint from India's Airtel network. While the subnet maintains clean abuse metrics and no persistent malicious activity has been observed, the moderate risk classification suggests potential for opportunistic abuse typical of mobile residential IPs.
Key Considerations for SOC Teams:
- Mobile residential IPs frequently used for credential stuffing and DDoS amplification
- Dynamic DNS associations may indicate changing infrastructure
- Monitor for lateral movement or command-and-control activity
- Consider geo-blocking if traffic is unexpected from India
Threat Level: MODERATE โ Enhanced monitoring recommended; blocking may be warranted based on organizational policy and additional contextual signals.
---
*Report generated: 2026-07-30 | Source: IPDebrief Threat Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Rashim Kapoor |
| ASN | AS24560 |
| Network Name | UPPAL-HYDERABAD-AP |
| CIDR Block | 117.98.192.0/19 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | telemedia-ap-dynamic-217.208.98.117.airtelbroadband.in |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | telemedia-ap-dynamic-217.208.98.117.airtelbroadband.in |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 35% | 2 | 2 |
| Overall | 22% | 6 | 7 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-26 15:19:49 UTC |
| Last Seen | 2026-07-30 07:57:55 UTC |
| Profile Built | 2026-07-30 08:10:40 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.