# INTELLIGENCE BRIEFING: 59.179.31.238/32
## Executive Summary
Target IP 59.179.31.238 is classified as Low Risk with a risk score of 25. The address operates as a web server within the MTNL network infrastructure in India. No active threat indicators or malicious behavior observed.
---
## Technical Profile
Network Attribution:
- ASN: 17813 (MTNL)
- Organization: Amarjeetkaur Bedi
- RIR: APNIC
- CIDR Block: 59.184.0.0/15
- BGP Prefix: 59.179.16.0/20
- Route Stability: Unstable (false)
Geolocation:
- Country: India (IN)
- Coordinates: 20.59°N, 78.96°E
- Accuracy: 1,500 km radius
- Geo Consensus: Confirmed
Infrastructure Classification:
- Service Type: Web Server
- Cloud/CDN/Proxy: Not identified
- Infrastructure: Standard web hosting
---
## Threat Intelligence
Risk Assessment:
- Overall Risk Score: 25/100 (Low Risk)
- Abuse Confidence Score: Not applicable
- Threat Persistence: 0 days
- Persistently Malicious: No
Threat Indicators:
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Status: 0 entries
- DNSBL Listings: 1 of 8 lists
Campaign Correlation:
- Campaign Likelihood: Not applicable
- Certificate Matches: 0
- Correlated IPs: 0
---
## Network Services & Fingerprint
Open Ports:
- TCP/80 (HTTP)
- TCP/443 (HTTPS)
- TCP/22 (SSH - Cisco SSH 1.25)
HTTP Fingerprint:
- Server: nginx
- HTTP Version: 1.1
- HSTS: Enabled (max-age=7884000)
- CSP: Not present
- HTTP/2: No
- Response Time: 1,305ms
TLS Certificate:
- Issuer: CN=IOS-Self-Signed-Certificate-2495010447
- Type: Self-signed
- SANs: None present
---
## Neighborhood Analysis (59.179.31.0/24)
Subnet Metrics:
- Abuse Density: 0.0 (Clean)
- Total Siblings: 2
- Active Siblings: 1
- Inherited Risk: 0
- Classification: Clean
Neighbor Risk Distribution:
- High Risk: 0
- Medium Risk: 1 (59.179.31.237, Risk Score: 50)
- Low Risk: 0
---
## Historical Observations
Signal Timeline: 17 total observations
- Classification History: Consistently clean
- Ownership Changes: 0
- Threat Observation Count: 0
- Recent Classification: Clean (2026-07-28)
Temporal Indicators:
- Threat Persistence Days: 0
- Ownership Stability: Stable (no changes)
- Route Changes (30d): 0
---
## Relationship Graph
Identified Relationships: 4
- Type: Same Network (MTNL)
- Target Type: Network
- Target Value: MTNL
---
## Recommended Actions
Security Posture: Minimal intervention required. Current risk score of 25 indicates low threat activity.
Monitoring Recommendations:
- Monitor neighboring IP 59.179.31.237 (risk score 50) for elevated activity
- Track route stability changes on BGP prefix 59.179.16.0/20
- Maintain baseline for 59.179.31.238 given current clean classification
Blocking Decision: No blocking recommended. Standard logging and monitoring sufficient.
---
*Report generated from IPDebrief intelligence platform data. All indicators reflect current observation state as of analysis timestamp.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Amarjeetkaur Bedi |
| ASN | AS17813 |
| Network Name | MTNL |
| CIDR Block | 59.184.0.0/15 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | 2024-04-23T09:59:54+00:00 |
| Valid Until | 2030-01-01T00:00:00+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 |
| Signature Algorithm | sha1RSA |
| Validity Period | 2078 days |
🛡️ Public Network Snapshot
| Origin ASN | AS17813 |
| Network Prefix | 59.179.16.0/20 |
| Route mapping | Found |
| HSTS | Enabled |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-16 22:52:43 UTC |
| Last Seen | 2026-08-31 21:27:49 UTC |
| Profile Built | 2026-08-31 21:32:27 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 25 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 59.179.31.238
Who owns the IP address 59.179.31.238?
59.179.31.238 is registered to Amarjeetkaur Bedi. The address falls within the 59.184.0.0/15 network block. Registration is held at APNIC.
Where is 59.179.31.238 located?
Geolocation data places 59.179.31.238 in Atlanta. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 59.179.31.238 malicious or safe?
59.179.31.238 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 59.179.31.238?
Responsive ports observed on 59.179.31.238 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.