IPDebrief

193.95.2.247

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 193.95.2.247

## Executive Summary

Intellective assessment identifies 193.95.2.247 as a low-risk network endpoint (risk score: 25) with conflicting geolocation data and limited threat indicators. The IP belongs to ATI - Agence Tunisienne Internet (AS31245) and presents minimal operational activity. No immediate blocking is warranted, but monitoring is recommended due to geolocation inconsistencies.

---

## Network Ownership & Classification

AttributeValue
**ASN**AS31245
**Organization**ATI - Agence Tunisienne Internet
**Netname**ORG-ATIA2-AFRINIC
**CIDR Block**193.95.2.0/24
**RIR**RIPE
**Service Classification**Firewalled / No Services

---

## Geolocation Intelligence

Discrepancy Detected: Profile indicates US (New York) while recent signals show Tunisia (TN). This inconsistency warrants attention.

Signal SourceLocation
Primary ProfileUS-NY
Latest ObservationTN (Tunisia)
Geo Sources1
ConsensusTrue

---

## Threat Indicators

---

## Neighborhood Analysis (193.95.2.0/24)

MetricValue
Subnet Abuse Density0
Total Siblings1
Active Siblings0
Threat Siblings0
Inherited Risk0
ClassificationNone

Neighbor IP: 193.95.2.161 (risk score: null)

---

## Historical Observations (11 Total)

Most recent activity recorded: 2026-07-29T22:29:09

Key Historical Signals:

---

## Network Control Plane

---

## Recommended Actions

Action TypeRecommendation
**Firewall**No specific rules generated (low risk score)
**Monitoring**Continue passive observation
**Investigation**Investigate geolocation discrepancy between US/TN data sources
**Threat Intel**Monitor for increased DNSBL listings or threat feed activity

---

## Intelligence Narrative

IP 193.95.2.247 operates within the ATI - Agence Tunisienne Internet network block (193.95.2.0/24). Despite a low risk score of 25, the IP presents notable intelligence gaps: geolocation data conflicts between US and Tunisia, and the subnet shows false route stability. The single DNSBL listing with high severity and 7 threat feed pulses suggest intermittent activity that has not yet escalated. No open services or active ports detected on the endpoint.

The neighborhood (193.95.2.0/24) exhibits zero abuse density with one sibling IP (193.95.2.161) of unknown status. This suggests the IP is not part of a coordinated attack infrastructure.

Recommended SOC Action: Maintain current monitoring posture. The low risk score combined with minimal neighborhood activity supports continued passive observation. The geolocation discrepancy should be flagged for further validation against other threat intel sources. No immediate blocking or firewall rules are warranted based on current data.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionUS-NY
CityNew York
TimezoneAmerica/New_York
Latitudeβ€”
Longitudeβ€”

🏒 Ownership & Registration

OrganizationATI - Agence Tunisienne Internet
ASNAS31245
Network NameORG-ATIA2-AFRINIC
CIDR Block193.95.2.0/24
RIRRIPE
CountryTN
Abuse Contactβ€”

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown β€” Insufficient routing data to classify
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
25%
11
reputation
0%
00
geolocation
0%
00
Overall16%44
Coverage: 4/6 dimensions Β· Data sufficiency: partial
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: TN, US

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-24 08:18:28 UTC
Last Seen2026-08-13 06:44:26 UTC
Profile Built2026-07-29 22:40:10 UTC
Data FreshnessLive
Signal Types16
Total Observations16
πŸ” 16 signal types Β· 16 observations collected
This report is generated from 16+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.