# IPDebrief Intelligence Briefing: 105.163.0.166/32
Classification: Moderate Risk (55/100) | Last Updated: 2026-07-29 | Status: Active
---
## Executive Summary
IP 105.163.0.166 is classified as a moderate-risk mobile endpoint with no observed malicious activity. The address operates on Safaricom's LTE network (Kenya) with geolocation data indicating London, GBβa discrepancy suggesting routing anomalies or mobile traffic masquerading. No open services detected; the endpoint appears firewalled with minimal network footprint.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 55/100 |
| **ASN** | 33771 (Domain Admin) |
| **CIDR Block** | 105.160.0.0/14 (afrinic) |
| **Network Role** | Mobile endpoint / Firewalled |
| **Connection Type** | LTE (Safaricom, Kenya) |
| **Geolocation** | Discrepant: GB (London) vs. KE (carrier data) |
| **DNSBL Status** | Listed on 3 of 8 threat feeds |
| **Open Ports/Services** | None detected |
| **Threat Indicators** | None identified |
---
## Threat Assessment
- Malicious Activity: No detected campaigns, known attacker status, or spam indicators
- Tor/Proxy: Not identified as Tor exit node or proxy
- Persistence: No persistent malicious behavior observed
- Control Plane: BGP prefix 105.163.0.0/24, route stability concerns flagged
- DNSBL Presence: 3 listings across 8 total listsβmonitor for escalation
---
## Neighborhood Context (105.163.0.0/24)
- Subnet Classification: Mostly clean
- Abuse Density: 0.2 (low-moderate)
- Risk Distribution: 0 high, 2 medium, 2 low
- Notable Neighbors:
- 105.163.0.146 (Risk: 55)
- 105.163.0.196 (Risk: 55)
- 105.163.0.82 (Risk: 30)
- 105.163.0.163 (Risk: 30)
---
## Observation History (15 Total Signals)
Recent observations show consistent low-to-moderate confidence signals for mobile network classification, with no escalation in threat indicators. No ownership changes or threat persistence observed.
---
## Recommended Actions
Immediate: Increase logging verbosity and review recent activity from this IP.
Firewall Implementation:
```bash
# iptables
iptables -A INPUT -s 105.163.0.166 -j DROP
# nftables
nft add rule inet filter input ip saddr 105.163.0.166 drop
# nginx
deny 105.163.0.166;
# pfSense
105.163.0.166/32
# Cloudflare WAF
Block: ip.src eq 105.163.0.166
# AWS WAF
Addresses: 105.163.0.166/32
Description: IPDebrief risk 55
```
---
## Analyst Notes
The geolocation discrepancy between GB and KE carrier data warrants monitoring. While current risk indicators remain moderate, the 3 DNSBL listings suggest potential prior abuse. Implement logging for 72 hours to validate baseline activity before applying blocking rules.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Domain Admin |
| ASN | AS33771 |
| Network Name | 105.160.0.0 - 105.163.255.255 |
| CIDR Block | 105.160.0.0/14 |
| RIR | AFRINIC |
| Country | KE |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 1 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-23 20:04:38 UTC |
| Last Seen | 2026-07-29 19:22:45 UTC |
| Profile Built | 2026-07-29 19:39:37 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 16 |
Full dossier details are available via our API.