## Intelligence Briefing: 196.0.122.122/32
Classification: HIGH RISK THREAT INDICATOR
Date: 2026-06-23
Executive Summary
IP address 196.0.122.122 is classified as high risk (score: 80/100) with elevated threat indicators. The address is associated with ASN 21491 (Kevin Mugaya Francis, ORG-UTL1-AFRINIC) and registered under the African Internet Registry (AFRINIC). Geolocation data indicates placement in Kampala, Uganda, Central Region.
Threat Profile
- Risk Score: 80/100 (High Risk)
- Threat Indicators: Listed on 8 DNS blacklist sources with 4 active listings showing high severity
- Service Role: Web Server (HTTP/HTTPS ports 80/443, SSH port 22)
- Server Banner: lighttpd/1.4.39
- Control Plane: BGP prefix 196.0.0.0/16, route stability: unstable, operator score: 0.1304 (Minimal)
- Reputation: No known campaigns, no Tor exit node activity, not flagged as known attacker or spam source
Network Context
The IP resides in subnet 196.0.122.0/24, classified as high abuse density. Neighborhood analysis identified 9 sibling IPs with the following risk distribution:
- High Risk: 2 (196.0.122.22, 196.0.122.242)
- Medium Risk: 7
- Low Risk: 0
Subnet abuse density: 0.222 (6 threat-sibling IPs out of 10 active siblings).
Historical Observations
Sixteen observations recorded over the monitoring period. Recent signals (2026-06-23) show:
- Multiple blacklist listings with high severity ratings
- Connection failures on HTTPS probes
- Operator score of 0 (Minimal)
- Threat observation count: 1
Related Entities
All relationship data points to ORG-UTL1-AFRINIC (same network classification). No correlated certificates or hostnames detected.
Recommended Actions
Immediate:
- Block 196.0.122.122/32 at perimeter firewall
- Increase logging verbosity for traffic analysis
- Monitor for associated subnet activity (196.0.122.0/24)
Firewall Rules:
- iptables: `iptables -A INPUT -s 196.0.122.122 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 196.0.122.122 drop`
- Cloudflare WAF: Block IP 196.0.122.122 (risk score 80)
- AWS WAF: Add 196.0.122.122/32 to blocklist
Assessment
The IP demonstrates elevated risk characteristics with DNS blacklist presence and unstable routing. The high-abuse subnet context suggests potential for coordinated malicious activity. Recommend blocking and monitoring for correlated traffic patterns from associated subnet addresses.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Kevin Mugaya Francis |
| ASN | AS21491 |
| Network Name | ORG-UTL1-AFRINIC |
| CIDR Block | 196.0.0.0/16 |
| RIR | AFRINIC |
| Country | UG |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | lighttpd/1.4.39 |
| HTTP Title | β |
| SSH Version | SSH-2.0-dropbear <????4g[$u??T?curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group1 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 29% | 2 | 3 |
| ownership | 21% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 13% | 1 | 1 |
| Overall | 23% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:05 UTC |
| Last Seen | 2026-06-23 03:43:10 UTC |
| Profile Built | 2026-06-23 03:50:03 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 17 |
Full dossier details are available via our API.