IPDebrief

182.75.234.236

IP Intelligence Dossier
Your IP: 216.73.217.34
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

Intelligence Briefing: IP 182.75.234.236/32

Executive Summary

The IP address 182.75.234.236 was classified as High Risk with a reputation score of 80. Analysis indicated the address was a blacklisted host listed on multiple DNS blocklists. Due to the high risk score and critical severity recommendation, immediate blocking is advised.

Ownership and Geolocation

The address belongs to ASN 9498 (Bharti Airtel Ltd.) under the Netname BHARTI-IN. Geolocation data placed the origin in India (IN), though geo-validation noted ICMP blocks. The network role was identified as a mobile carrier IP (Airtel LTE/5G) operating as a Web Server.

Technical and Threat Profile

* Ports: TCP/80 (HTTP) and TCP/443 (HTTPS) were open.

* Server Fingerprint: Nginx server; Powered by Express.

* Security Headers: HSTS enabled; CSP and Permissions Policy headers were missing.

* DNS: PTR hostname resolved to nsg-static-236.234.75.182-airtel.com. SPF records existed, but DMARC was not configured.

* Threat Indicators: The address was categorized as a Blacklisted Host with a DNSBL listed count of 4. No active attacker indicators or known campaigns were detected.

Confidence and Validity

The confidence level for this profile was Very Low (0.2232), and data sufficiency was recorded at 0.8333. Despite the low confidence, the risk score and blacklisting status warrant defensive action.

Recommended Action

Block the address at the firewall and perimeter.

* iptables: `iptables -A INPUT -s 182.75.234.236 -j DROP`

* nginx: `deny 182.75.234.236;`

* pf: `block in quick on egress from 182.75.234.236`

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฎ๐Ÿ‡ณ India
Regionโ€”
CityBoston
Timezoneโ€”
Latitudeโ€”
Longitudeโ€”

๐Ÿข Ownership & Registration

OrganizationNetwork Administrator
ASNAS9498
Network NameBHARTI-IN
CIDR Block182.75.128.0/18
RIRAPNIC
CountryIN
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRnsg-static-236.234.75.182-airtel.com
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesnsg-static-236.234.75.182-airtel.com

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPF2/3 domains
DMARC0/3 domains
FCrDNSNot verified
DNSSECNot signed
CAANot configured
Domains Checked3 domains

โ˜๏ธ Network Classification

InfrastructureMobile
Service PurposeWeb Server
Network TierUnknown โ€” Insufficient routing data to classify
Mobile

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
Closed Ports22, 25, 3389, 8080, 8443 (2 open / 7 scanned)
Servernginx
HTTP Titleโ€”

๐Ÿ” TLS Certificate

A self-signed certificate was detected. This is common for development servers, internal services, or IoT devices.
โš ๏ธ
CN=uservsftpd
Issued by CN=uservsftpd
Self-signed: Yes
SANsNone
Valid From2019-07-01T15:58:34+00:00
Valid Until2119-06-07T15:58:34+00:00
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period36500 days
Serial Number00925F2A1D715F4C64
Thumbprint0544A1C64AF2B1CEB875A4F7DD2A338507751754

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
38%
24
routing
13%
11
services
37%
25
ownership
25%
12
reputation
0%
00
geolocation
19%
22
Overall22%814
Coverage: 5/6 dimensions ยท Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-08-17 04:21:53 UTC
Last Seen2026-09-27 14:43:29 UTC
Profile Built2026-09-27 14:43:56 UTC
Data FreshnessLive
Signal Types24
Total Observations43
๐Ÿ” 24 signal types ยท 43 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.