# IP INTELLIGENCE BRIEFING
Target: 152.59.161.18/32
Classification: Low Risk | Date: 2026-07-30
Analyst: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
IP 152.59.161.18 presents a low-risk profile (Risk Score: 25/100) with no active threat indicators. The address is associated with ASN 55836 within BGP prefix 152.56.0.0/14. Recent observations indicate the IP is geolocated to India (West Bengal) and shows DNSSEC validation. No open services or active campaigns detected. Recommended classification: Monitor but no immediate blocking required.
---
## RISK PROFILE
| Metric | Value |
|---|---|
| Overall Risk Score | 25 (Low Risk) |
| Provider Score | 0 |
| Authority Score | 0 |
| Operator Score | 0.1304 (Minimal) |
| Stability Label | N/A |
| Reputation Status | Low Risk |
Threat Indicators: None detected
Blacklist Status: Listed on 1 of 8 DNSBLs (max severity: high)
Campaign Affiliation: No known campaigns or threat feed matches
Attacker Status: Not flagged as known attacker or spam source
---
## TECHNICAL CHARACTERISTICS
Network Classification:
- ASN: 55836
- BGP Prefix: 152.56.0.0/14
- Origin ASN: 55836
- Route Stability: Unstable (isRouteStable: false)
- RPKI State: Not verified
- RIR Registry: Pending assignment
DNS/Network Services:
- DNSSEC: Valid
- PTR Hostnames: None resolved
- Open Ports: None
- TLS Certificates: None
- HTTP Services: None
- Forward Resolution: No A/AAAA records
Behavioral Analysis:
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: 0
- Auto-Banned: No
---
## GEOLOCATION DATA
Latest Observation (2026-07-30T11:25:02Z):
- Country: India (IN)
- Region: West Bengal
- Coordinates: 22.5643°N, 88.3693°E
- Geolocation Source: MaxMind GeoLite2-City
- Geo Confidence: 0.70
---
## OBSERVATION HISTORY (7 Signals)
Recent observations show consistent low-risk signals:
- 2026-07-30T11:25:02Z: Geolocation update (India/West Bengal)
- 2026-07-30T11:24:29Z: Operator score assessment (0.1304, label: Minimal)
- 2026-07-30T11:24:16Z: DNSBL listing activity (1 of 8 lists, high severity)
- 2026-07-30T11:24:13Z: DNSSEC validation confirmed (valid)
No significant risk escalation observed over monitoring period.
---
## NEIGHBORHOOD ANALYSIS (152.59.161.0/24)
Subnet Statistics:
- Total Siblings: 2
- Active Siblings: 2
- Abuse Density: 0%
- Inherited Risk: 0
Sibling IPs:
| IP Address | Risk Score | Classification |
|---|---|---|
| 152.59.161.70 | 25 | Low Risk |
| 152.59.161.117 | 0 | Low Risk |
No high-risk or medium-risk neighbors detected.
---
## RELATIONSHIP GRAPH
External Connections: None detected
The IP shows no relationships to other entities (subnets, hostnames, organizations, or certificates) within the intelligence graph.
---
## RECOMMENDED ACTIONS
Current Risk Level: Low (Score: 25/100)
Recommended Firewall Rule: None required
WAF Policy: Standard allow (no blocking recommendations)
Action Rationale:
- No active threat indicators or malicious behavior patterns
- No open services or ports for exploitation
- DNSSEC validation indicates legitimate infrastructure
- Single DNSBL listing likely related to historical activity
- No evidence of active attacker behavior
Monitoring Recommendation: Continue passive monitoring. No immediate blocking required.
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-RELIANCEJIO-IN |
| ASN | AS55836 |
| Network Name | RELIANCEJIO-IN |
| CIDR Block | 152.56.0.0/14 |
| RIR | ARIN |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 09:38:57 UTC |
| Last Seen | 2026-07-30 11:24:08 UTC |
| Profile Built | 2026-07-30 11:35:56 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.