# INTELLIGENCE BRIEFING: 223.181.61.239/32
Classification: Moderate Risk | Status: Active | Date: 2026-07-30
---
## EXECUTIVE SUMMARY
IP address 223.181.61.239 is classified as Moderate Risk (Score: 40). The address is assigned to mobile carrier Airtel (Bharti Airtel Ltd.) under ASN 24560 (IRT-BHARTI-MO-IN) and is associated with the Manaser network block (223.181.56.0/21). No active threat indicators were detected, though the IP appears on 2 of 8 DNSBL lists.
---
## OWNERSHIP & GEOLOCATION
| Attribute | Value |
|---|---|
| **Organization** | IRT-BHARTI-MO-IN |
| **Netname** | Manaser |
| **ASN** | 24560 |
| **RIR** | APNIC |
| **CIDR Block** | 223.181.56.0/21 |
| **Abuse Contact** | ip.misuse@airtel.com |
Geolocation Discrepancy Noted:
- Profile indicates Atlanta, GA, US
- Historical signals show Gurgaon/New Delhi, India
- Mobile carrier data (MCC: 404, MNC: 10) confirms IN mobile network
- Recommend validating geolocation through additional sources
---
## THREAT INDICATORS
| Indicator | Status |
|---|---|
| **Risk Score** | 40 / 100 |
| **Known Attacker** | No |
| **Tor Exit Node** | No |
| **Spam Source** | No |
| **Blacklist Count** | 0 |
| **DNSBL Listed** | 2 / 8 lists |
| **Open Services** | None (Firewalled) |
| **Threat Feeds** | None |
| **Campaign Correlation** | None |
---
## NETWORK CONTEXT
- Network Role: Mobile IP (Airtel LTE/5G)
- Service Purpose: Firewalled / No Services
- Connection Type: Mobile
- Operator Score: 0.1304 (Minimal)
- Route Stability: False (route changes observed)
- RPKI State: Not assessed
- DNSSEC: Valid
---
## OBSERVATION HISTORY
- Total Observations: 12
- Latest Signals: 2026-07-30
- Threat Persistence: 0 days
- Ownership Changes: 0
Recent activity shows consistent attribution to Bharti Airtel infrastructure with no escalation in threat signals.
---
## NEIGHBORHOOD ANALYSIS
- Subnet: 223.181.61.239/24
- Abuse Density: 0.00
- Neighbor Risk Distribution: None detected
- Related Entities: Manaser network (same network block)
---
## RECOMMENDED ACTIONS
1. Monitor: Maintain monitoring on this IP due to moderate risk classification and DNSBL presence.
2. Block (Optional): Consider blocking if traffic is unexpected, though no active threat indicators detected.
3. Investigate: Validate geolocation discrepancy through independent sources; may indicate spoofing or routing anomaly.
4. Contact: Abuse reporting available via ip.misuse@airtel.com if malicious activity is observed.
5. Allow: Permissive action appropriate for legitimate mobile traffic from this carrier.
---
## CONCLUSION
This IP represents mobile network traffic from Airtel's Indian infrastructure with moderate risk scoring primarily attributable to DNSBL listings rather than active threat activity. No immediate threat indicators detected. Recommend continued monitoring and validation of geolocation data.
Analyst Notes: Geographic inconsistency warrants further investigation. Mobile context suggests consumer/business mobile device traffic rather than fixed infrastructure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-BHARTI-MO-IN |
| ASN | AS24560 |
| Network Name | Manaser |
| CIDR Block | 223.181.56.0/21 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-25 14:53:08 UTC |
| Last Seen | 2026-07-30 04:24:56 UTC |
| Profile Built | 2026-07-30 04:40:49 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.