Threat Intelligence Briefing: IP 122.165.91.5/32
Summary:
The IP address 122.165.91.5/32 was observed during a recent analysis and was linked to a range of activities. The data indicates that this IP address was associated with a known service provider and exhibited traffic patterns consistent with legitimate use. However, there were also instances of suspicious activity that warrant further monitoring.
Provider and Ownership:
- The IP address 122.165.91.5/32 is associated with a major telecommunications service provider, suggesting that it is used for legitimate network operations.
- The address is registered under the provider's domain, indicating it is likely part of their infrastructure.
Activity Observations:
- Normal Activity: The address was primarily observed participating in standard network communication, including HTTP and HTTPS traffic, which aligns with expected behavior for a service provider.
- Suspicious Activity: There were intermittent spikes in outbound traffic that did not match the typical pattern for this address. These spikes were directed towards a range of IP addresses known for hosting command-and-control (C2) servers, raising concerns about potential misuse.
Relationships and Associations:
- The IP address has been seen communicating with several external IP addresses that have been flagged in threat intelligence databases for hosting malicious content or being part of botnet activities.
- There is evidence of attempted connections to known phishing domains, suggesting possible exploitation attempts.
Neighborhood Data:
- The surrounding IP addresses are primarily associated with the same service provider, indicating a controlled network environment.
- However, adjacent IPs have occasionally exhibited similar traffic patterns to the suspicious activity observed from 122.165.91.5/32, suggesting potential lateral movement or shared misuse.
Recommendations for SOC Analysts:
1. Monitoring: Implement enhanced monitoring of traffic originating from and directed to 122.165.91.5/32, especially focusing on outbound connections to flagged IP ranges.
2. Traffic Analysis: Conduct a detailed traffic analysis to identify any recurring patterns or anomalies that could indicate malicious activity.
3. Threat Hunting: Engage in proactive threat hunting within the network to uncover any signs of compromise or misuse related to this IP.
4. Incident Response Planning: Prepare an incident response plan in case further investigation confirms malicious use, including steps for containment and mitigation.
Conclusion:
While the primary use of 122.165.91.5/32 appears legitimate, the presence of suspicious activity necessitates vigilance. Continuous monitoring and analysis are essential to ensure that any potential threats are identified and addressed promptly.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Network Administrator for ABTS TN |
| ASN | AS24560 |
| Network Name | ABTS-TN-DSL-9111-chn |
| CIDR Block | 122.165.64.0/19 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | abts-tn-static-005.91.165.122.airtelbroadband.in |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | abts-tn-static-005.91.165.122.airtelbroadband.in |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 22% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 20% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-08 23:18:01 UTC |
| Last Seen | 2026-06-26 18:10:32 UTC |
| Profile Built | 2026-06-25 10:47:43 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 21 |
Full dossier details are available via our API.