# IP Intelligence Briefing: 171.61.175.140/32
Classification: Low Risk / Residential Mobile
Assessment Date: Current (based on observation data)
---
## Executive Summary
IP address 171.61.175.140 is classified as a low-risk residential mobile endpoint operating within the Bharti Airtel network infrastructure (ASN 24560). The IP shows minimal threat indicators with no blacklist entries, no active services, and a low overall risk score of 15. While geographic data exhibits some inconsistencies between US and India reporting, the IP demonstrates stable ownership characteristics consistent with residential mobile usage.
---
## Network Profile & Ownership
| Attribute | Value |
|---|---|
| **IP Address** | 171.61.175.140/32 |
| **ASN** | 24560 (Bharti Airtel Ltd.) |
| **Organization** | Network Administrator for ABTS DEL |
| **CIDR Block** | 171.61.128.0/18 |
| **Registration RIR** | APNIC |
| **Network Name** | ABTS-DSL-DEL |
Geolocation Data:
- Reported locations show geographic inconsistency: US (Massachusetts/Boston) vs India (Delhi/Noida)
- This discrepancy is consistent with mobile carrier routing behavior where geolocation signals may originate from different network nodes
- Mobile carrier: Airtel (Bharti Airtel Ltd.), MCC 404, MNC 10, LTE/5G technology
---
## Threat Assessment
Overall Risk Score: 15 (Low Risk)
Threat Indicators:
- Blacklist count: 0
- Known attacker: False
- Tor exit node: False
- Spam source: False
- Reputation sources: None detected
- Active threat campaigns: None
Network Services:
- Open ports: None detected
- TLS certificate: None
- HTTP services: None
- Classification: Firewalled / No Services
Control Plane:
- DNSBL listed on 1 of 8 lists
- RPKI state: Not applicable
- Route stability: False
- Route changes (30d): 0
---
## Observation History Analysis
Total observations recorded: 12
Recent Activity (July 29, 2026):
- ASN attribution: AS24560 (Bharti Airtel Ltd.)
- Geolocation signals: Noida, India (UP) and Phase III, New Delhi
- Ownership signals: ABTS-DSL-DEL network block
- Threat signals: 1 signal flagged with has_threats: true (requires context correlation)
- Control plane operator score: 0.1304 (Minimal)
Temporal Indicators:
- Ownership changes: 0
- Threat persistence days: 0
- Threat observation count: 0
- Persistently malicious: False
---
## Neighborhood Analysis
Subnet: 171.61.175.140/24
Risk Distribution:
- High risk neighbors: 0
- Medium risk neighbors: 1
- Low risk neighbors: 0
Notable Neighbor: 171.61.175.3 (Risk Score: 55)
- This sibling IP exhibits medium risk classification
- Located in same /24 subnet block
- Abuse density for subnet: 0
Relationship Graph:
- Connections: 2 (both to same network ABTS-DSL-DEL)
- No hostname, certificate, or organization relationships identified
---
## Security Recommendations
Immediate Actions: None required based on current risk profile
Monitoring Considerations:
1. Monitor neighbor IP 171.61.175.3 for elevated activity (risk score 55)
2. Review geographic inconsistency in reporting (US vs India signals)
3. Track mobile carrier routing patterns for baseline comparison
Firewall Rules: No specific blocking recommended at this time. IP may be allowed or monitored based on organizational policy for residential mobile traffic.
---
## Intelligence Conclusion
IP 171.61.175.140 represents a benign residential mobile endpoint with no active threat indicators. The low risk score (15), absence of blacklist entries, and firewalled status indicate normal residential usage. The single medium-risk sibling IP (171.61.175.3) warrants periodic monitoring but does not necessitate immediate action. Geographic reporting inconsistencies are consistent with mobile carrier network behavior and do not indicate malicious activity.
Recommendation: Allow traffic with standard residential/mobile IP policy. Maintain awareness of neighborhood IP 171.61.175.3 for anomaly detection.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Network Administrator for ABTS DEL |
| ASN | AS24560 |
| Network Name | ABTS-DSL-DEL |
| CIDR Block | 171.61.128.0/18 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-21 19:02:57 UTC |
| Last Seen | 2026-07-29 10:18:31 UTC |
| Profile Built | 2026-07-29 10:28:40 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.