Intelligence Briefing for IP 122.187.227.144/32
Summary:
IP 122.187.227.144/32 is a static IP address associated with a known organization based on WHOIS data, which provides some contextual understanding of its legitimate use. This IP has been observed in various network activities, and its neighborhood data suggests a mix of legitimate services and potentially malicious connections.
Ownership and Organization:
- WHOIS Data: The IP 122.187.227.144/32 is registered to a telecommunications company based in the region of Asia. The registration details indicate that the IP is used for business-related activities.
- Organization Profile: The owner has been operational for several years, primarily providing internet services to clients in both commercial and residential sectors.
Activity Observations:
- Traffic Patterns: Historical data indicates regular outbound traffic patterns associated with typical business operations, including data synchronization with known cloud service providers.
- Malware Detection: The IP has been linked to a few incidents where it was observed communicating with command and control (C2) servers, suggesting potential misuse by attackers leveraging this IP for malicious activities.
- Botnet Activity: There have been sporadic reports of the IP being involved in distributed denial-of-service (DDoS) attacks, although these incidents appear to be opportunistic rather than systemic.
Network Relationships:
- Known Peers and Affiliates: The IP's neighborhood includes a mix of IPs associated with legitimate corporate services and those flagged for suspicious activities, such as phishing and malware distribution.
- Communication Patterns: The IP frequently communicates with other IPs within its organization, indicating a structured network environment. However, occasional unsolicited connections to external IPs raise red flags.
Neighborhood Data:
- Proximity Analysis: The surrounding IP addresses reveal a blend of entities, some of which are registered to the same organization, while others are associated with unrelated entities. A few neighboring IPs have been flagged for suspicious activities, including unauthorized access attempts.
- Risk Assessment: The proximity to both legitimate and potentially malicious IPs suggests a heightened risk of association with cyber threats, either through direct compromise or indirect association.
Actionable Insights for SOC Teams:
- Monitoring: Continuous monitoring of traffic patterns from and to this IP is recommended to detect anomalies that may indicate misuse or compromise.
- Threat Intelligence Sharing: Collaborate with threat intelligence platforms to share and receive updates on any emerging threats linked to this IP.
- Incident Response Preparedness: Develop incident response strategies tailored to potential threats associated with this IP, focusing on rapid identification and mitigation of any malicious activities.
This intelligence briefing provides a comprehensive overview of IP 122.187.227.144/32, highlighting both its legitimate use and potential security risks. SOC teams are advised to maintain vigilance and incorporate this information into their broader security posture.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-BHARTI-IN |
| ASN | AS9498 |
| Network Name | โ |
| CIDR Block | 122.187.224.0/19 |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | nsg-corporate-144.227.187.122.airtel.in |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | nsg-corporate-144.227.187.122.airtel.in |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 30% | 3 | 4 |
| reputation | 26% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 25% | 12 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:36 UTC |
| Last Seen | 2026-06-26 18:10:32 UTC |
| Profile Built | 2026-06-22 12:26:40 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 27 |
Full dossier details are available via our API.