## IP Intelligence Briefing: 27.63.216.26
Date: Current Analysis
Risk Assessment: Moderate Risk (Score: 40/100)
Executive Summary
IP address 27.63.216.26 is a residential mobile endpoint associated with Bharti Airtel's Indian network infrastructure. The IP demonstrated moderate risk characteristics with firewalling services detected but no active open ports. Historical analysis indicates stable network registration with no persistent malicious activity.
Network Infrastructure
- ASN: 45609 (IRT-BHARTI-MO-IN)
- Organization: IRT-BHARTI-MO-IN (Bharti Airtel Ltd.)
- CIDR Block: 27.63.208.0/20
- RIR: APNIC
- NetName: KOLKATA-WEST-BENGAL
- Abuse Contact: ip.misuse@airtel.com
- Mobile Carrier: Airtel (MCC: 404, MNC: 10, Technology: LTE/5G)
Geolocation
- Country: India (IN)
- Region: Kerala
- Coordinates: 9.98°N, 76.27°E
- Timezone: Asia/Kolkata
- Geolocation Consensus: True (Single source, validated)
Network Services & Threat Indicators
- Service Status: Firewalled / No Services Detected
- Open Ports: None
- TLS Certificate: None
- DNS Records: No forward resolution
- PTR Hostnames: None
- Email Authentication: SPF and DMARC not configured
- Blacklist Count: 0 (DNSBL: 2 of 8 lists)
- Tor Exit Node: False
- Known Attacker: False
- Spam Source: False
Risk Breakdown
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
- Operator Score: 0.1304 (Label: Minimal)
- Abuse Confidence Score: Not calculated
Historical Analysis
12 observation signals recorded, most recent dated 2026-07-30:
- Network Registration: High confidence signals (0.90-0.95) confirming ASN and RIR registration
- Geolocation: Multiple signals with confidence ranging from 0.30 to 0.90, showing India-based positioning
- Threat Indicators: No persistent malicious activity detected
- Threat Persistence Days: 0
- Campaign Likelihood: None
Network Relationships
- 2 relationships identified, both classified as "Same Network" (KOLKATA-WEST-BENGAL)
- No cross-network correlations detected
Subnet Analysis (/24)
- Subnet: 27.63.216.26/24
- Neighbor Count: 0
- Abuse Density: 0
- High Risk Siblings: 0
- Medium Risk Siblings: 0
- Low Risk Siblings: 0
Control Plane Assessment
- Route Stability: False
- AS Path: Not available
- RPKI State: Not available
- IRR Consistency: Not available
- DNSSEC Valid: True
- MOAS Status: False
- Route Changes (30d): 0
Recommended Security Actions
Based on risk profile, the following defensive measures are recommended:
Firewall Rules:
- `iptables -A INPUT -s 27.63.216.26 -j DROP`
- `nft add rule inet filter input ip saddr 27.63.216.26 drop`
- `nginx: deny 27.63.216.26;`
Cloud/WAF Implementation:
- Cloudflare WAF: Block IP 27.63.216.26 (Expression: `ip.src eq 27.63.216.26`)
- AWS WAF: Add address 27.63.216.26/32 to block list
Analyst Notes
This IP represents a mobile residential endpoint within Bharti Airtel's infrastructure. The moderate risk score (40) is primarily driven by DNSBL listings and lack of route stability. No active threat indicators, open services, or malicious campaigns were observed. The IP is firewalled with no services exposed. SOC teams may consider blocking based on organizational policy thresholds, though the risk level warrants case-by-case evaluation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-BHARTI-MO-IN |
| ASN | AS45609 |
| Network Name | KOLKATA-WEST-BENGAL |
| CIDR Block | 27.63.208.0/20 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 35% | 2 | 2 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 14% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 09:39:27 UTC |
| Last Seen | 2026-07-30 11:48:01 UTC |
| Profile Built | 2026-07-30 11:58:26 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.