# IP INTELLIGENCE BRIEFING
Target: 182.77.70.223/32
Classification: Mobile Carrier Residential IP
Risk Score: 65/100 (Moderate Risk)
Report Date: 2026-07-30
---
## EXECUTIVE SUMMARY
IP address 182.77.70.223 is a residential mobile carrier endpoint operated by Bharti Airtel (ASN 24560) in Delhi, India. The IP carries a moderate risk score of 65/100, primarily attributed to DNSBL presence (3 of 8 lists) and mobile carrier classification. No active malicious campaigns, open services, or persistent threat indicators detected. The IP is currently firewalled with no services exposed.
---
## NETWORK ATTRIBUTES
| Attribute | Value |
|---|---|
| **ASN** | 24560 |
| **Organization** | Network Administrator (BTNM-Mumbai) |
| **Country** | India (IN) |
| **City** | Delhi, National Capital Territory of Delhi |
| **Mobile Carrier** | Airtel (Bharti Airtel Ltd.) |
| **CIDR Block** | 182.77.64.0/18 |
| **Connection Type** | LTE/5G Mobile |
| **DNS PTR** | abts-mum-dynamic-223.70.77.182.airtelbroadband.in |
---
## THREAT INDICATORS
| Indicator | Status |
|---|---|
| **Known Attacker** | No |
| **Tor Exit Node** | No |
| **Spam Source** | No |
| **Blacklist Count** | 3/8 DNSBL lists |
| **Open Ports** | None detected |
| **Active Services** | None (Firewalled) |
| **Campaign Association** | No known campaigns |
| **DNSBL Listed** | Yes (3 lists) |
---
## TEMPORAL ANALYSIS
- Observations: 14 recorded signals
- Threat Persistence: 0 days
- Ownership Changes: 0
- Recent Activity: All observations from July 30, 2026
- Persistence Assessment: Not persistently malicious
---
## NEIGHBORHOOD ANALYSIS
- Subnet: 182.77.70.223/24
- Abuse Density: 0%
- Total Siblings: 0
- Threat Siblings: 0
- Risk Distribution: No sibling IPs identified
---
## RELATIONSHIP GRAPH
- Network Association: BTNM-Mumbai (multiple references)
- DNS Associations: abts-mum-dynamic-223.70.77.182.airtelbroadband.in (4 entries)
---
## RECOMMENDED ACTIONS
| Action | Severity |
|---|---|
| **Increase logging verbosity and review recent activity** | High |
Firewall Rules (Recommended)
```bash
# iptables
iptables -A INPUT -s 182.77.70.223 -j DROP
# nftables
nft add rule inet filter input ip saddr 182.77.70.223 drop
# nginx
deny 182.77.70.223;
# pfSense
182.77.70.223/32
# Cloudflare WAF
ip.src eq 182.77.70.223 โ BLOCK
```
---
## ANALYST NOTES
The moderate risk score (65/100) is driven by DNSBL presence and mobile carrier classification. The IP shows no evidence of active exploitation, hosting services, or campaign participation. However, the risk score warrants monitoring due to the elevated threshold. The residential mobile nature means traffic may be from legitimate end-user devices but could also be exploited for compromised endpoints.
Recommendation: Monitor inbound connections from this IP. If the organization permits mobile carrier traffic, apply rate limiting rather than hard blocking to avoid affecting legitimate users. If blocking is required, implement the firewall rules provided and maintain logs for forensic review.
---
*Report generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Network Administrator |
| ASN | AS24560 |
| Network Name | BTNM-Mumbai |
| CIDR Block | 182.77.64.0/18 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | abts-mum-dynamic-223.70.77.182.airtelbroadband.in |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | abts-mum-dynamic-223.70.77.182.airtelbroadband.in |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 22:49:54 UTC |
| Last Seen | 2026-07-31 13:31:51 UTC |
| Profile Built | 2026-07-31 00:06:32 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.