# IP Intelligence Briefing: 59.98.5.66/32
## Executive Summary
IP address 59.98.5.66/32 is a moderate-risk BSNL (Bharat Sanchar Nigam Limited) infrastructure endpoint located in Kanniyakumari, Tamil Nadu, India. The IP exhibits no known malicious indicators but is associated with two DNSBL listings. Recommended for monitoring but no immediate blocking required based on current threat profile.
## Ownership and Registration
- Organization: IRT-BSNL-IN (Indian Telephone Industries)
- ASN: 9829 (BSNL)
- Network Block: 59.98.0.0/19
- Netname: BSNL-GSM-EastZone
- Country: India (IN)
- Region: Tamil Nadu
- City: Kanniyakumari
- RIR: APNIC
- Registration: APNIC registry
## Threat Assessment
- Risk Score: 40 (Moderate)
- Provider Score: 0
- Authority Score: 0
- Blacklist Count: 0
- Abuse Confidence: Not applicable
- Known Campaigns: None detected
Key Findings:
- Not classified as a known attacker, spam source, or Tor exit node
- No threat indicators detected in historical scans
- No open ports or active services detected (firewalled/no services)
- Not associated with any malware campaigns or certificate matches
## Network Classification
- Infrastructure Type: Telecommunications/ISP
- Service Purpose: Firewalled / No Services
- Connection Type: Not residential, cloud, CDN, or proxy
- Mobile Carrier: Not detected
- DNS Resolution: static.bb.rch.59.98.5.66.bsnl.in
## Technical Observations
- DNS Records: Forward resolution failed; PTR hostname resolves to BSNL domain
- Email Auth: SPF and DMARC records present on associated domains
- Control Plane:
- Origin ASN: 9829
- BGP Prefix: 59.98.0.0/20
- Route Stability: False
- DNSBL Listed: 2 of 8 total lists
- Operator Score: 0.1304 (Minimal)
- Geolocation Validation: Plausible (8,006.9 km RTT distance, 341ms avg RTT)
- Traceroute: 20 hops, 8 timeouts, transit via Comcast networks
## Historical Analysis
Observation history shows 17 data points with consistent characteristics:
- Recent scan activity (2026-07-29 timeframe)
- No ownership changes detected
- Zero persistent malicious activity
- Geolocation signals consistently indicate India region
- No escalation in threat persistence or observation counts
## Neighborhood Analysis
- Subnet: 59.98.5.66/24
- Total Siblings: 0 active
- Abuse Density: 0
- Threat Siblings: 0
- No neighboring IPs flagged as high or medium risk
## Relationships
- Network Associations: BSNL-GSM-EastZone (multiple entries)
- DNS Associations: static.bb.rch.59.98.5.66.bsnl.in (multiple entries)
- No external organization or certificate associations
## Recommended Actions
Based on the moderate risk score (40), the following defensive measures are recommended:
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 59.98.5.66 -j DROP
# nftables
nft add rule inet filter input ip saddr 59.98.5.66 drop
# nginx
deny 59.98.5.66;
# pfSense
59.98.5.66/32
```
Cloud WAF Configuration:
- Cloudflare WAF: Block with expression `ip.src eq 59.98.5.66`
- AWS WAF: Add IP 59.98.5.66/32 to rule group
## Intelligence Conclusion
IP 59.98.5.66/32 represents a BSNL telecommunications infrastructure endpoint with a moderate baseline risk score. The absence of open services, no open ports, and zero known malicious indicators suggest this is legitimate ISP infrastructure. However, the two DNSBL listings warrant ongoing monitoring. Current recommendation: Monitor but no immediate blocking required unless additional threat signals emerge.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-BSNL-IN |
| ASN | AS9829 |
| Network Name | BSNL-GSM-EastZone |
| CIDR Block | 59.98.0.0/19 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static.bb.rch.59.98.5.66.bsnl.in |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | static.bb.rch.59.98.5.66.bsnl.in |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| Closed Ports | 22, 25, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 46% | 2 | 3 |
| routing | 22% | 1 | 1 |
| services | 46% | 2 | 3 |
| ownership | 45% | 2 | 3 |
| reputation | 23% | 1 | 2 |
| geolocation | 45% | 2 | 3 |
| Overall | 38% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-24 08:19:03 UTC |
| Last Seen | 2026-08-13 06:45:12 UTC |
| Profile Built | 2026-07-30 04:56:47 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.