# IP Intelligence Briefing: 105.214.94.25/32
Classification: Low Risk | Risk Score: 25 | Status: No Active Threat Indicators
## Executive Summary
IP 105.214.94.25 is a mobile subscriber address with low overall risk profile. The address shows no known malicious activity, no blacklist presence, and no associated threat campaigns. Network classification indicates mobile infrastructure (MTN carrier, South Africa) with services described as "Firewalled / No Services." No immediate defensive action required.
## Technical Profile
Ownership & Network:
- ASN: 16637 (Dijon Mannie / ORG-VSA1-AFRINIC)
- CIDR Block: 105.208.0.0/12
- RIR: AFRINIC
Geolocation:
- Country: South Africa (ZA)
- Region: Gauteng
- City: Johannesburg
- Coordinates: -26.23°N, 28.06°E
- Timezone: Africa/Johannesburg
Network Classification:
- Type: Mobile
- Carrier: MTN (MTN Group Ltd., MCC: 655, MNC: 10)
- Technology: LTE/5G
- Services: Firewalled / No Services
- Not identified as proxy, VPN, Tor, CDN, cloud, or hosting infrastructure
## Threat Indicators
- Risk Score: 25 (Low)
- Abuse Confidence: Not applicable
- Blacklist Count: 0
- DNSBL Listings: 1 of 8 total lists
- Known Attack Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
## Historical Observations
Ten observations recorded, most recent on 2026-07-30:
- Geolocation signals consistently reporting Johannesburg, South Africa
- Operator score classified as "Minimal" (0.1304)
- No evidence of persistent malicious activity
- Threat observation count: 0
- IP not flagged as persistently malicious
## Neighborhood Analysis
- Subnet: 105.214.94.25/24
- Abuse Density: 0
- Threat Siblings: 0
- Total Siblings: 0
- No neighboring IPs showing elevated risk profiles
## Relationship Graph
Three relationships identified, all linked to ORG-VSA1-AFRINIC network ownership. No additional organizational or hostname relationships detected.
## Recommended Actions
No specific firewall rules or mitigation recommendations generated. Current risk profile does not warrant blocking or restriction. Standard monitoring practices recommended.
---
*Intelligence compiled from IPDebrief platform. Data sourced from geolocation providers, threat feeds, DNS analysis, and network classification databases.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dijon Mannie |
| ASN | AS16637 |
| Network Name | ORG-VSA1-AFRINIC |
| CIDR Block | 105.208.0.0/12 |
| RIR | AFRINIC |
| Country | ZA |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 1 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-26 03:08:09 UTC |
| Last Seen | 2026-07-30 05:57:02 UTC |
| Profile Built | 2026-07-30 06:14:25 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.