# IP Intelligence Briefing: 223.184.235.130
## Executive Summary
The target IP address 223.184.235.130/32 presents a low-risk profile according to current reputation scoring (risk score: 0), but recent observation history indicates conflicting threat indicators including blacklist activity with high severity ratings. The IP is geolocated to Boston, MA, USA, though ASN data associates it with Bharti Airtel Ltd. (ASN 45609) in India, indicating potential geolocation discrepancies requiring verification.
## Current Risk Profile
| Metric | Value |
|---|---|
| Risk Score | 0 |
| Provider Score | 0 |
| Authority Score | 0 |
| Reputation | Low Risk |
| Blacklist Count | 0 |
| Active Threat Indicators | None |
Network Classification: Firewalled / No Services
Open Ports: None detected
Services: No active services identified
## Geolocation Analysis
| Attribute | Profile | History |
|---|---|---|
| Country | US | IN (India) |
| Region/City | US-MA, Boston | Not specified |
| ASN | Not detected | 45609 (Bharti Airtel Ltd.) |
| Network Prefix | Not detected | 223.184.234.0/23 |
Note: Significant geolocation inconsistency between profile and historical data. Profile indicates US/MA while ASN data shows Indian allocation.
## Threat Intelligence
Recent observations (2026-07-29) reveal:
- Blacklist Activity: IP detected on 8 total lists with 1 current listing at "high" severity (confidence: 0.85)
- Port Scanning: Port scanning activity detected (confidence: 0.70)
- DNS Resolution: No PTR record; DNSSEC validation present
- No Active Threats: No known attacker status, not a spam source, not a Tor exit node
## Neighborhood Analysis
Subnet: 223.184.235.130/24
- Neighbor Count: 0
- Abuse Density: 0
- Risk Distribution: All categories (high/medium/low) at 0
- Classification: No inherited risk from subnet peers
## Relationship Graph
No related entities detected in the relationship graph. No associated hostnames, organizations, certificates, or linked subnets identified.
## Observation History
Ten total observations recorded. Key signals include:
- Port scanning activity detected on 2026-07-29T07:27:28
- Blacklist listings with high severity (confidence: 0.85)
- DNSSEC validation confirmed (confidence: 0.90)
- ASN registration: 2010-09-14 via APNIC registry
## Behavioral Indicators
| Indicator | Status |
|---|---|
| Active Attacker | No |
| Honeypot Hits | 0 |
| Enumeration Strikes | 0 |
| WAF Violations | 0 |
| Total Incidents | 0 |
| Persistently Malicious | No |
## Recommended Actions
Based on the risk profile and observed behavior:
1. Monitor: Continue monitoring due to geolocation discrepancies and intermittent blacklist activity
2. Verify Geolocation: Correlate with upstream routing data to resolve US/IN conflict
3. No Immediate Blocking: Risk score remains 0 with no active threat indicators
4. Firewall Rules: No specific firewall rules required per current profile
## Intelligence Assessment
The IP address 223.184.235.130 currently presents minimal immediate threat (risk score 0), but the geolocation inconsistency (US profile vs. Indian ASN) and recent high-severity blacklist detection warrant continued observation. The "Firewalled / No Services" classification suggests the IP may be a dormant or reserved address, yet scanning activity indicates it has been probed. Recommend correlation with upstream routing data and upstream ISP records to resolve the geolocation discrepancy and clarify the operational status of this address.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | IRT-BHARTI-MO-IN |
| ASN | AS45609 |
| Network Name | CHANDIVALI-MUMBAI-MUMBAI |
| CIDR Block | 223.184.128.0/17 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 4% | 1 | 1 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-21 06:47:20 UTC |
| Last Seen | 2026-07-29 07:26:29 UTC |
| Profile Built | 2026-07-29 07:31:12 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 15 |
Full dossier details are available via our API.