# Intelligence Briefing: IP 171.61.30.74/32
## Executive Summary
The IP address 171.61.30.74/32 was assessed as Moderate Risk with a risk score of 55/100. The address is associated with Airtel mobile network infrastructure in Ludhiana, Punjab, India, operating on 4G/LTE or 5G technology. No active threat indicators or persistent malicious behavior were detected.
## Technical Profile
Ownership & Network:
- ASN: 24560 (Airtel India Limited)
- Organization: Network Administrator for ABTS DEL
- CIDR Block: 171.61.0.0/18
- RIR: APNIC (Asia-Pacific Network Information Centre)
- Network Name: ABTS-DSL-MPCG
Geolocation:
- Country: India (IN)
- Region: Punjab
- City: Ludhiana (coordinates: 30.91°N, 75.85°E)
- Timezone: Asia/Kolkata
Connectivity:
- Mobile Carrier: Airtel (Bharti Airtel Ltd.)
- Technology: LTE/5G
- Connection Type: Mobile (MCC: 404, MNC: 10)
DNS & Infrastructure:
- PTR Hostnames: None detected
- Forward Resolution: Not confirmed
- Hosted Domains: 0
- Email Authentication: No SPF/DMARC records
- Reverse DNS: Inactive
Security Services:
- Open Ports: None detected
- TLS Certificate: None
- HTTP Banner: None
- Service Classification: Firewalled / No Services Detected
## Threat Assessment
Current Risk Level: Moderate (55/100)
Threat Indicators:
- Blacklist Count: 0
- DNSBL Listings: 3 of 8 total lists
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Known Campaigns: None
- Threat Feeds: None populated
Control Plane:
- BGP Prefix: 171.61.28.0/22
- Route Stability: Not stable
- DNSSEC: Valid
- IRR Consistency: Not evaluated
- RPKI State: Not evaluated
## Observation History
Ten signal observations were recorded during the analysis period. Key observations include:
- Ownership and geolocation signals remained consistent across observations
- Abuse email: dsltac2north.unoc@airtel.com
- RIR registration confirmed via APNIC
- No ownership changes detected
- No persistent malicious activity flagged
- Risk persistence days: 0
## Network Relationships
Two relationships were identified:
- Same Network: ABTS-DSL-MPCG (network classification)
- Same Network: ABTS-DSL-MPCG (network classification)
## Neighborhood Analysis
Subnet: 171.61.30.74/24
- Neighbor Count: 1
- Abuse Density: 0
- Risk Distribution: 1 Medium, 0 High, 0 Low
Identified Neighbor:
- IP: 171.61.30.44
- Risk Score: 40
- Authority Score: 50
## Recommended Actions
Based on the elevated risk score (55/100), the following security measures are recommended:
Monitoring:
- Increase logging verbosity and review recent activity from this IP address
Firewall Rules:
- iptables: `iptables -A INPUT -s 171.61.30.74 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 171.61.30.74 drop`
- nginx: `deny 171.61.30.74;`
- pfSense: `171.61.30.74/32`
- Cloudflare WAF: Block with expression `ip.src eq 171.61.30.74`
- AWS WAF: Add to rule with CIDR `171.61.30.74/32`
## Analyst Notes
The IP address demonstrates characteristics consistent with a mobile device connection on Airtel's LTE/5G network infrastructure. The elevated risk score without active threat indicators suggests the address may be flagged due to network-level activity patterns or historical reputation factors. The absence of open services and firewalling indicates the endpoint is not actively hosting network services. Correlation with neighboring IP 171.61.30.44 (risk score 40) suggests potential co-location within the same residential or mobile subnet.
Classification: Moderate Risk / Monitor
Priority: Medium
Action Required: Implement monitoring and firewall rules as recommended
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Network Administrator for ABTS DEL |
| ASN | AS24560 |
| Network Name | ABTS-DSL-MPCG |
| CIDR Block | 171.61.0.0/18 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-28 16:13:54 UTC |
| Last Seen | 2026-07-30 17:39:16 UTC |
| Profile Built | 2026-07-30 17:53:31 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.