IPDebrief

202.164.42.142

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 202.164.42.142/32

## Executive Summary

IP address 202.164.42.142 is a residential endpoint from India operating on IRT-ECLTELECOM-IN (INFOTEL CONNECT) infrastructure. The IP carries a moderate risk score of 40 but shows no active threat indicators. Network neighborhood analysis indicates a clean subnet with minimal abuse density.

## Infrastructure Profile

## Threat Assessment

Risk Score: 40 (Moderate Risk)

IndicatorStatus
Known AttackerNegative
Tor Exit NodeNegative
Spam SourceNegative
Active Threat IndicatorsNone
Blacklist Count0
DNSBL Listings2 of 8 total
Known CampaignsNone

The IP is not classified as hosting, CDN, VPN, proxy, cloud, or mobile infrastructure. No open services or TLS certificates are actively advertised on the endpoint.

## Network Context

## DNS Analysis

## Historical Activity

18 observations recorded on 2026-07-25 show consistent residential classification with no evidence of persistent malicious activity. Risk signals have remained stable with no escalation trends.

## Related Entities

## Recommended Actions

Based on the moderate risk profile, the following firewall rules are recommended:

iptables:

```bash

iptables -A INPUT -s 202.164.42.142 -j DROP

```

nftables:

```bash

nft add rule inet filter input ip saddr 202.164.42.142 drop

```

nginx:

```nginx

deny 202.164.42.142;

```

Cloudflare WAF:

```json

{

"description": "Block 202.164.42.142 — IPDebrief risk score 40",

"action": "block",

"filter": {

"expression": "ip.src eq 202.164.42.142"

}

}

```

AWS WAF:

```json

{

"Addresses": ["202.164.42.142/32"],

"Description": "IPDebrief risk 40"

}

```

## Analyst Notes

The IP address exhibits a moderate risk score primarily due to DNSBL presence and residential classification. No active malicious behavior has been observed. The associated domain (dukeindia.com) implements SPF and DMARC records. The subnet shows zero abuse density with no threat-sibling IPs. Recommended action is monitoring or blocking based on organizational policy for moderate-risk residential IPs.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇮🇳 India
RegionPB
CityLudhiana
TimezoneAsia/Kolkata
Latitude31.54
Longitude75.91

🏢 Ownership & Registration

OrganizationIRT-ECLTELECOM-IN
ASNAS17917
Network NameDUKE_FASHIONS_INDIA_LTD
CIDR Block202.164.42.128/28
RIRAPNIC
CountryIN
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRdukeindia.com
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesdukeindia.com

🔐 DNS Hygiene

Hygiene Score40% (Fair)
SPF1/2 domains
DMARC2/2 domains
FCrDNSNot verified
DNSSECNot signed
CAANot configured
Domains Checked2 domains

☁️ Network Classification

InfrastructureResidential
Service PurposeWeb Server
Network TierEnd-User — Residential ISP endpoint
Residential

🔌 Services & Open Ports

PortServiceProtocolBanner
80httptcp—
443httpstcp—
Closed Ports22, 25, 3389, 8080, 8443 (2 open / 7 scanned)
ServerWeb server detected
HTTP Title—
⚠ Unusual for residential — open services on a home connection may indicate self-hosting, compromise, or misconfigured networking equipment.

🔐 TLS Certificate

A self-signed certificate was detected. This is common for development servers, internal services, or IoT devices.
⚠️
E=help@nebtree.com, CN=CN, OU=S3Y9NF0JC40001M-00900b44d434, O=NEBERO SYSTEMS PVT LTD, L=Punjab, S=Punjab, C=IN
Issued by E=help@nebtree.com, CN=CN, OU=S3Y9NF0JC40001M-00900b44d434, O=NEBERO SYSTEMS PVT LTD, L=Punjab, S=Punjab, C=IN
Self-signed: Yes
SANsNone
Valid From2018-04-25T14:04:54+00:00
Valid Until2028-04-22T14:04:54+00:00
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period3650 days

🛡️ Public Network Snapshot

Origin ASNAS17917
Network Prefix202.164.42.0/24
Route mappingFound
Certificates in transparency logs20 certificates
HSTSNot detected
CSPNot detected
HTTP/2Not detected

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
0%
00
Overall12%33
Coverage: 3/6 dimensions · Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-09 13:32:14 UTC
Last Seen2026-09-29 03:07:30 UTC
Profile Built2026-09-23 07:49:36 UTC
Data FreshnessLive
Signal Types24
Total Observations25
🔍 24 signal types · 25 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 202.164.42.142

Who owns the IP address 202.164.42.142?

202.164.42.142 is registered to IRT-ECLTELECOM-IN. The address falls within the 202.164.42.128/28 network block. Registration is held at APNIC.

Where is 202.164.42.142 located?

Geolocation data places 202.164.42.142 in Ludhiana, PB, India. The local time zone is Asia/Kolkata. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 202.164.42.142 malicious or safe?

202.164.42.142 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 202.164.42.142?

The reverse DNS (PTR) record for 202.164.42.142 is dukeindia.com. This hostname is not forward-confirmed, so it should be treated as a weak signal.

What ports are open on 202.164.42.142?

Responsive ports observed on 202.164.42.142 include 80, 443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.

Is 202.164.42.142 a VPN, proxy, or data center address?

202.164.42.142 is classified as a residential network based on network ownership and behavioural analysis.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.