IP Intelligence Briefing: 128.185.208.42
Date: 2026-06-17
---
**1. Core Profile**
- Risk Score: 80 (High Risk)
- Ownership:
- ASN: 9498
- Organization: IRT-BHARTI-IN (Bharti Airtel Ltd.)
- Geolocation: India (New Phase III), Mobile Carrier (Airtel)
- Network Role: Mobile network (LTE/5G), no public services or hosting.
---
**2. Threat Indicators**
- DNSBL Listings: 5/8 (high severity), including potential spam or malicious activity.
- No Direct Threat Indicators: No malware, phishing, or known attacker associations.
- Stability: Unstable routing (route changes in 30 days), minimal operator trust score (0.2174).
---
**3. Historical Observations**
- Recent Activity (2026-06-17):
- Listed in 5 DNSBLs (high severity).
- DNSSEC and CAA records present but no domain resolution.
- No TLS/HTTP services or open ports detected.
- Long-Term Trend: 23 observations over time, with increasing DNSBL exposure.
---
**4. Network Relationships**
- Subnet: 128.185.208.0/24 (BHARTI-IN)
- Linked Entities:
- Same ASN (9498) and mobile carrier (Airtel).
- No hostname or certificate associations.
---
**5. Neighborhood Analysis**
- Subnet Abuse Density: 0% (no malicious neighbors).
- Active Siblings: 0/1 (no neighboring IPs detected).
---
**6. Recommendations**
- Monitor: Track DNSBL listings and potential spam activity.
- Block: Consider blocking the IP due to high risk score and DNSBL associations.
- Investigate: Verify if the mobile network is compromised or if the IP is part of a botnet.
Note: The IP is associated with a mobile carrier, suggesting it may be a compromised device or part of a mobile-specific attack vector. SOC teams should prioritize monitoring for unusual traffic patterns or lateral movement.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-BHARTI-IN |
| ASN | AS9498 |
| Network Name | BHARTI-IN |
| CIDR Block | 128.185.128.0/18 |
| RIR | ARIN |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.9 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 48% | 2 | 5 |
| routing | 32% | 2 | 3 |
| services | 29% | 2 | 3 |
| ownership | 29% | 3 | 4 |
| reputation | 27% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 33% | 12 | 21 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:39 UTC |
| Last Seen | 2026-06-26 18:10:35 UTC |
| Profile Built | 2026-06-22 13:17:51 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 30 |
Full dossier details are available via our API.