# IP Intelligence Briefing: 193.95.2.247
## Executive Summary
Intellective assessment identifies 193.95.2.247 as a low-risk network endpoint (risk score: 25) with conflicting geolocation data and limited threat indicators. The IP belongs to ATI - Agence Tunisienne Internet (AS31245) and presents minimal operational activity. No immediate blocking is warranted, but monitoring is recommended due to geolocation inconsistencies.
---
## Network Ownership & Classification
| Attribute | Value |
|---|---|
| **ASN** | AS31245 |
| **Organization** | ATI - Agence Tunisienne Internet |
| **Netname** | ORG-ATIA2-AFRINIC |
| **CIDR Block** | 193.95.2.0/24 |
| **RIR** | RIPE |
| **Service Classification** | Firewalled / No Services |
---
## Geolocation Intelligence
Discrepancy Detected: Profile indicates US (New York) while recent signals show Tunisia (TN). This inconsistency warrants attention.
| Signal Source | Location |
|---|---|
| Primary Profile | US-NY |
| Latest Observation | TN (Tunisia) |
| Geo Sources | 1 |
| Consensus | True |
---
## Threat Indicators
- Risk Score: 25 (Low Risk)
- DNSBL Listings: 1 of 8 total lists (high severity)
- Threat Feeds: 7 pulses detected
- Abuse Confidence: Not scored
- Tor/Proxy/Vpn: Negative across all categories
- Known Attacker: False
- Spam Source: False
---
## Neighborhood Analysis (193.95.2.0/24)
| Metric | Value |
|---|---|
| Subnet Abuse Density | 0 |
| Total Siblings | 1 |
| Active Siblings | 0 |
| Threat Siblings | 0 |
| Inherited Risk | 0 |
| Classification | None |
Neighbor IP: 193.95.2.161 (risk score: null)
---
## Historical Observations (11 Total)
Most recent activity recorded: 2026-07-29T22:29:09
Key Historical Signals:
- Multiple threat feed pulses (7 total)
- DNSBL listings across 8 lists
- Operator score: 0.1304 (Minimal)
- Ownership changes: 0
- Threat persistence days: 0
- Not persistently malicious
---
## Network Control Plane
- Origin ASN: AS31245
- BGP Prefix: 193.95.2.0/24
- Route Stable: False
- MOAS: False
- DNSSEC Valid: True
- IRP Consistency: N/A
- Route Changes (30d): 0
---
## Recommended Actions
| Action Type | Recommendation |
|---|---|
| **Firewall** | No specific rules generated (low risk score) |
| **Monitoring** | Continue passive observation |
| **Investigation** | Investigate geolocation discrepancy between US/TN data sources |
| **Threat Intel** | Monitor for increased DNSBL listings or threat feed activity |
---
## Intelligence Narrative
IP 193.95.2.247 operates within the ATI - Agence Tunisienne Internet network block (193.95.2.0/24). Despite a low risk score of 25, the IP presents notable intelligence gaps: geolocation data conflicts between US and Tunisia, and the subnet shows false route stability. The single DNSBL listing with high severity and 7 threat feed pulses suggest intermittent activity that has not yet escalated. No open services or active ports detected on the endpoint.
The neighborhood (193.95.2.0/24) exhibits zero abuse density with one sibling IP (193.95.2.161) of unknown status. This suggests the IP is not part of a coordinated attack infrastructure.
Recommended SOC Action: Maintain current monitoring posture. The low risk score combined with minimal neighborhood activity supports continued passive observation. The geolocation discrepancy should be flagged for further validation against other threat intel sources. No immediate blocking or firewall rules are warranted based on current data.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | ATI - Agence Tunisienne Internet |
| ASN | AS31245 |
| Network Name | ORG-ATIA2-AFRINIC |
| CIDR Block | 193.95.2.0/24 |
| RIR | RIPE |
| Country | TN |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 1 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-24 08:18:28 UTC |
| Last Seen | 2026-08-13 06:44:26 UTC |
| Profile Built | 2026-07-29 22:40:10 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.