# IP Intelligence Briefing: 59.145.209.90/32
## Executive Summary
The target IP 59.145.209.90 is assessed as Low Risk with a risk score of 0. The address is associated with Bharti Airtel mobile network infrastructure and operates as a web server. No malicious indicators, threat feeds, or blacklist entries were identified. Recommended security posture: MONITOR with no immediate blocking required.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **IP Address** | 59.145.209.90/32 |
| **CIDR Block** | 59.145.209.80/28 |
| **ASN** | 9498 (Bharti Airtel Ltd.) |
| **Organization** | Network Administrator / Bharti Airtel Ltd. |
| **RIR** | APNIC |
| **Reputation** | Low Risk |
| **Risk Score** | 0 (0/100) |
---
## Geolocation Analysis
Geolocation data presents inconsistencies typical of mobile network infrastructure:
- Primary Location: US (Newark, NJ, America/New_York timezone)
- Secondary Location: IN (Haldwani, UT - from AlienVault OTX)
- Connection Type: Mobile (LTE/5G)
- Mobile Carrier: Airtel (MCC: 404, MNC: 10)
The conflicting geolocation signals suggest this IP may be part of a mobile content delivery network or roaming infrastructure.
---
## Network Services
| Service | Status | Details |
|---|---|---|
| **HTTPS (443/tcp)** | Open | Primary service |
| **TLS Certificate** | Issued | CN=FGT60D4614010659, O=Fortinet Ltd. |
| **HTTP Status** | 200 | Valid response |
| **HSTS** | Enabled | max-age=15552000 |
| **CSP** | Enabled | frame-ancestors 'self' |
| **X-Frame-Options** | SAMEORIGIN | Present |
---
## Threat Intelligence
Risk Indicators
- Abuse Confidence Score: Not applicable (low risk)
- Blacklist Count: 0
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Known Campaigns: None
Control Plane Data
- BGP Prefix: 59.145.209.0/24
- Origin ASN: 9498
- Route Stability: Unstable (isRouteStable: false)
- DNSSEC Valid: True
- DNSBL Listed: 0 of 8 lists
---
## Historical Observations
Total Observations: 16
Recent signal timeline (2026-07-27):
- 22:05:43 UTC: Network classification scan (confidence: 0.30)
- 22:04:07 UTC: Banner analysis (confidence: 0.30)
- 22:03:04 UTC: Ownership verification (confidence: 0.85)
- 22:02:48 UTC: HTTP fingerprinting (confidence: 0.80)
- 22:01:47 UTC: Geolocation from AlienVault OTX (confidence: 0.75)
Temporal Analysis:
- Ownership changes: 0
- Threat persistence days: 0
- Is persistently malicious: False
- Threat observation count: 0
---
## Relationship Graph
Total Relationships: 4
- All relationships point to same network: OCCL-259403-Patiala
- No external hostname or certificate relationships detected
---
## Neighborhood Analysis
Subnet: 59.145.209.90/24
- Total Neighbors: 0
- High Risk Neighbors: 0
- Medium Risk Neighbors: 0
- Low Risk Neighbors: 0
- Abuse Density: 0 (clean subnet)
---
## Security Recommendations
Current Status
Risk Score: 0
Action: NO IMMEDIATE ACTION REQUIRED
Recommended Security Posture
1. Monitor the IP address for any changes in behavior
2. Log traffic to/from this address for baseline analysis
3. No firewall rules recommended at this time
Context for SOC Analysts
This IP represents mobile network infrastructure (Bharti Airtel) operating a web server. The clean risk profile, absence of threat indicators, and zero abuse density in the neighborhood suggest benign operation. The geolocation inconsistencies are characteristic of mobile/CDN routing and do not indicate malicious activity.
---
## Conclusion
IP 59.145.209.90 is a low-risk address associated with legitimate mobile network infrastructure. No blocking or mitigation actions are warranted based on current intelligence. Continue standard monitoring practices.
*Report generated: 2026-07-27*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Network Administrator |
| ASN | AS9498 |
| Network Name | OCCL-259403-Patiala |
| CIDR Block | 59.145.209.80/28 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | — |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | 2019-07-20T12:41:15+00:00 |
| Valid Until | 2029-07-20T12:41:15+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 3653 days |
🛡️ Public Network Snapshot
| Origin ASN | AS9498 |
| Network Prefix | 59.145.209.0/24 |
| Route mapping | Found |
| HSTS | Enabled |
| CSP | Enabled |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 46% | 2 | 3 |
| routing | 22% | 1 | 1 |
| services | 46% | 2 | 3 |
| ownership | 32% | 2 | 2 |
| reputation | 23% | 1 | 2 |
| geolocation | 32% | 2 | 2 |
| Overall | 33% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-15 10:09:24 UTC |
| Last Seen | 2026-09-02 13:23:25 UTC |
| Profile Built | 2026-08-29 13:06:45 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 59.145.209.90
Who owns the IP address 59.145.209.90?
59.145.209.90 is registered to Network Administrator. The address falls within the 59.145.209.80/28 network block. Registration is held at APNIC.
Where is 59.145.209.90 located?
Geolocation data places 59.145.209.90 in Newark, US-NJ, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 59.145.209.90 malicious or safe?
59.145.209.90 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 59.145.209.90?
Responsive ports observed on 59.145.209.90 include 443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.
Is 59.145.209.90 a VPN, proxy, or data center address?
59.145.209.90 is classified as a mobile network based on network ownership and behavioural analysis.