## Intelligence Briefing: 193.104.222.16/32
Executive Summary
IP 193.104.222.16 was assessed as Low Risk with a risk score of 25. The address operates as a firewalled endpoint with no active services, no open ports, and no TLS certificates. While the IP maintains a low individual risk profile, the surrounding /24 subnet exhibits mixed abuse characteristics with 8 medium-risk and 0 high-risk neighbors.
Technical Profile
- ASN/Provider: AS42201 (MNT-PVDATANET), RIR: RIPE
- Geolocation: London, England, GB (accuracy radius: 750km)
- DNS Resolution: 193-104-222-16.cust.norisab.net (norisab.net)
- Network Role: Firewalled / No Services
- Classification: Not CDN, proxy, VPN, Tor, hosting, or mobile
Threat Indicators
- Blacklist Status: Listed on 1 of 8 DNSBLs
- Known Indicators: None detected
- Tor/Spam/Attacker: Not flagged
- Campaign Correlation: No matches
- Persistence: No persistent malicious behavior observed
Neighborhood Analysis (193.104.222.0/24)
The subnet contains 19 sibling IPs with a risk distribution of 11 low, 8 medium, and 0 high-risk addresses. Notable neighbors include:
- 193.104.222.24 (risk: 65)
- 193.104.222.7, .8, .159 (risk: 50)
- Multiple IPs with risk scores of 25-40
The subnet abuse density was measured at 0.2778, indicating moderate activity levels.
Historical Observations
19 signal observations were recorded, with the most recent on 2026-06-25 showing minimal operator scoring (0.1304). Historical data includes geolocation inconsistencies with some records referencing Swedish network associations (SE-PVDATANET-20191115) and Telia Company (AS1299), suggesting potential routing or registration discrepancies.
Relationship Graph
- Network Associations: Multiple entries linked to SE-PVDATANET-20191115
- DNS Associations: 13 hostname entries resolving to 193-104-222-16.cust.norisab.net
- Control Plane: Route stability flagged as false; 0 route changes over 30 days
Security Recommendations
No specific firewall rules or blocking recommendations were generated due to the low-risk classification. The IP is not actively malicious but warrants monitoring due to:
1. DNSBL listing (1 of 8 lists)
2. Mixed-risk neighborhood context
3. Historical geolocation inconsistencies
SOC Analyst Action: Monitor for behavioral changes. No immediate blocking required. Correlate with any inbound/outbound traffic patterns from this address for additional context.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | MNT-PVDATANET |
| ASN | AS42201 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 193-104-222-16.cust.norisab.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 193-104-222-16.cust.norisab.net |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 19% | 2 | 2 |
| Overall | 18% | 9 | 11 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-09 11:33:48 UTC |
| Last Seen | 2026-06-25 15:49:50 UTC |
| Profile Built | 2026-06-25 15:58:47 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.