# IP Intelligence Briefing: 223.178.210.65/32
Classification: Low Risk (Score: 25)
Date: Current Intelligence Cycle
Status: Active Monitoring Recommended
---
## Executive Summary
IP 223.178.210.65 is a mobile carrier-allocated IPv4 address operated by Bharti Airtel Ltd. under ASN 24560 (Netname: BHARTI-MO-IN) within the APNIC RIR. The endpoint registers as Low Risk with no active threat indicators, no known attacker history, and no spam source classification. The IP shows no open services and no forward DNS resolution, consistent with mobile subscriber infrastructure.
---
## Ownership and Network Context
| Attribute | Value |
|---|---|
| ASN | 24560 |
| Organization | Rahul Jain |
| Network Name | BHARTI-MO-IN |
| Country | India (IN) |
| Region/City | Chandigarh |
| CIDR Block | 223.176.0.0/12 |
| Mobile Carrier | Airtel (Bharti Airtel Ltd.) |
| Technology | LTE/5G |
---
## Threat Indicators
- Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not applicable
- Blacklist Status: Listed on 1 of 8 DNSBL lists
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Correlation: None detected
- Active Threat Indicators: None
---
## Network Role and Services
- Infrastructure Type: Mobile Subscriber
- Service Status: Firewalled / No Services
- Open Ports: None detected
- TLS Certificate: Not available
- HTTP Title: Not available
- Forward DNS: Not confirmed
- PTR Hostnames: None recorded
- Email Auth: SPF/DMARC not configured (no domain)
---
## Control Plane Assessment
- BGP Prefix: 223.178.210.0/23
- Route Stability: Not stable
- RPKI State: Not applicable
- IRR Consistency: Not applicable
- Operator Score: 0.1304 (Minimal)
- MoAS Status: No
- DNSSEC: Valid
---
## Neighborhood Analysis (223.178.210.0/24)
| Metric | Value |
|---|---|
| Total Siblings | 5 |
| Active Siblings | 4 |
| Abuse Density | 0% (Clean) |
| Inherited Risk | 0 |
| Threat Siblings | 0 |
Neighbor IP Risk Summary:
- 223.178.210.115: Risk Score 55 (Medium)
- 223.178.210.167: Risk Score 40 (Medium)
- 223.178.210.203: Risk Score 40 (Medium)
- 223.178.210.220: Risk Score 40 (Medium)
---
## Observation History
Total observations tracked: 15
Recent Signal Activity:
- Ownership: Consistent attribution to Rahul Jain, Airtel, APNIC RIR (confidence: 0.90โ0.95)
- Classification: Clean subnet with 0 abuse density (confidence: 0.40)
- Services: No open ports detected across multiple scans (confidence: 0.70)
- Threat Persistence: No persistent malicious behavior observed
- Ownership Changes: 0 changes recorded
- Threat Observation Count: 0
Temporal analysis indicates stable ownership without threat escalation patterns.
---
## Relationship Graph
Two relationships identified:
- Same Network: BHARTI-MO-IN (network entity)
- Same Network: BHARTI-MO-IN (network entity)
Limited relationship footprint consistent with mobile carrier IP allocation.
---
## Recommended Actions
Firewall Rules (iptables/nftables)
```bash
# No blocking recommended for Low Risk mobile IP
# Allow traffic on port 443 only if business requirement exists
```
WAF Rules
- No Cloudflare/AWS WAF rules recommended
- No blocking required
Monitoring Guidance
- Monitor for service initiation if IP appears in traffic logs
- No immediate threat response required
- Neighborhood IPs show medium risk scores (40โ55); consider contextual awareness
---
## Intelligence Conclusion
IP 223.178.210.65 is a legitimate mobile carrier endpoint with no evidence of malicious activity. The Low Risk classification is supported by clean neighborhood metrics, absence of threat indicators, and consistent ownership history. SOC analysts should treat inbound traffic from this IP as legitimate unless additional context indicates otherwise. No defensive actions are required at this time.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Rahul Jain |
| ASN | AS24560 |
| Network Name | BHARTI-MO-IN |
| CIDR Block | 223.176.0.0/12 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 13:24:19 UTC |
| Last Seen | 2026-07-29 13:51:39 UTC |
| Profile Built | 2026-07-29 14:05:00 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.