# IP Intelligence Briefing: 120.56.165.124/32
## Executive Summary
IP address 120.56.165.124/32 is classified as High Risk (Risk Score: 80) with no active threat indicators currently detected. The IP belongs to MTNL infrastructure under the organization "Amarjeetkaur Bedi" (ASN: 9829). The address appears to be firewalled with no open services, though control plane data indicates 4 DNSBL listings out of 8 total checks.
## Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 80 (High Risk) |
| **ASN** | 9829 |
| **Organization** | Amarjeetkaur Bedi (MTNL) |
| **Country** | India (IN) |
| **Region** | Union Territory of Puducherry |
| **CIDR Block** | 120.56.0.0/13 |
| **RIR** | APNIC |
| **Status** | Firewalled / No Services |
| **Blacklist Count** | 0 |
| **DNSBL Listed** | 4 of 8 lists |
## Network & Infrastructure Analysis
Service Status: No open ports or active services detected. The IP is classified as "Firewalled / No Services." No TLS certificates, HTTP banners, or domain resolutions observed.
Control Plane: Route stability is flagged as unstable (isRouteStable: false). The IP appears in 4 DNSBL lists, suggesting historical reputation concerns. Operator score: 0.1304 (Minimal).
Geographic Validation: ICMP probing was blocked during validation. The IP shows geographic distance of 7,823.5km from validation point with 1,500km accuracy radius.
## Historical Observations
Analysis of 15 observation signals (most recent: 2026-07-31) reveals:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Classification: Not persistently malicious
Recent signals indicate consistent ownership under MTNL with no changes. Ownership records point to APNIC RIR with abuse contact: abusemtnl@bol.net.in.
## Neighborhood Analysis
Subnet: 120.56.165.124/24
- Abuse Density: 0 (Clean)
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 0
No neighboring IPs detected with threat indicators. The /24 subnet shows clean classification with no inherited risk from adjacent addresses.
## Threat Indicators
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Correlation: No matching certificates or correlated IPs
- Campaign Likelihood: Not detected
## Recommended Actions
1. Monitor: Despite high risk score, no active threat indicators warrant immediate blocking. Monitor for changes in service status or DNSBL listings.
2. Block if: New threat indicators emerge or DNSBL listings increase.
3. Contact: For abuse reporting, use abusemtnl@bol.net.in
4. Context: The high risk score may reflect historical reputation or infrastructure metadata rather than active malicious activity.
## Intelligence Assessment
The IP address presents a low immediate threat despite the high risk score. The absence of open services, combined with a clean neighborhood profile and no active threat indicators, suggests the risk classification may be based on historical data or network metadata. SOC analysts should maintain monitoring but no immediate defensive action is required unless new threat indicators surface.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Amarjeetkaur Bedi |
| ASN | AS9829 |
| Network Name | MTNL |
| CIDR Block | 120.56.0.0/13 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 17:11:12 UTC |
| Last Seen | 2026-08-01 22:41:12 UTC |
| Profile Built | 2026-07-31 03:19:02 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.