# INTELLIGENCE BRIEFING: 196.117.126.168/32
Classification: LOW RISK | Risk Score: 15/100 | Date: 2026-07-24
## EXECUTIVE SUMMARY
IP address 196.117.126.168 presents low-risk threat characteristics with minimal observable malicious activity. The address is associated with ASN 36925 operating within BGP prefix 196.117.64.0/18. Current service state indicates firewalled configuration with no detected open ports or active services.
## OBSERVATION HIGHLIGHTS
Current Risk Profile
- Risk Score: 15 (Low Risk)
- Reputation: Low Risk
- Blacklist Status: Listed on 1 of 8 DNSBLs
- Abuse Confidence: Not scored
Geographic Indicators
- Primary Country: GB (United Kingdom)
- Secondary Geo Data: Casablanca-Settat, MA (Morocco) - conflicting signals observed
- Geo Consensus: False (multiple conflicting sources)
- Accuracy: Multiple geo sources but consensus not achieved
Network Infrastructure
- ASN: 36925
- BGP Prefix: 196.117.64.0/18
- Route Stability: False (route changes detected)
- Traceroute: 29 hops, 16 timed-out hops (transit networks include Comcast, Cogent)
- Service Purpose: Firewalled / No Services
DNS & Email
- PTR Records: None observed
- DNSSEC: Valid
- Forward Resolution: 0 hostnames resolved
- Email Auth: No SPF/DMARC records
- Forward Resolution Count: 0
## THREAT INDICATORS
| Indicator | Status |
|---|---|
| Tor Exit Node | Not detected |
| Known Attacker | Not flagged |
| Spam Source | Not flagged |
| Active Attacker | Not flagged |
| Honeypot Hits | 0 |
| Enumeration Strikes | 0 |
| WAF Violations | 0 |
| Total Incidents | 0 |
Recent Signal History (9 observations)
- Latest: 2026-07-24 09:49:41 UTC
- DNSSEC Valid: Confirmed
- Listed Count: 1 DNSBL listing (medium severity)
- Signal Confidence Range: 0.17 - 0.90
## NETWORK CONTEXT
Subnet Analysis (196.117.126.0/24)
- Abuse Density: 0
- Total Siblings: 0
- Active Siblings: 0
- Threat Siblings: 0
- High/Medium Risk Neighbors: None detected
Relationship Graph
- Related Entities: None identified
- Associated Hostnames: None
- Related Organizations: None
## RECOMMENDED ACTIONS
Firewall Rules
No immediate firewall blocking required based on current risk profile.
Monitoring Recommendations
- Monitor for route stabilization in 196.117.64.0/18 prefix
- Watch for geo-geolocation consensus convergence
- Track DNSBL listing context (if applicable to traffic flow)
Priority Level
LOW - No active threat indicators requiring immediate response.
## ANALYST NOTES
The IP demonstrates minimal threat persistence with zero observed malicious activities. Geographic data inconsistency (GB vs MA) warrants periodic revalidation but does not indicate active threat. Route instability flag suggests network infrastructure changes; monitor for potential future risk profile shifts. No adjacent IP threats detected in /24 subnet.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | ISP Orange Morocco |
| ASN | AS36925 |
| Network Name | 196.112.0.0 - 196.119.255.255 |
| CIDR Block | 196.112.0.0/13 |
| RIR | AFRINIC |
| Country | MA |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS36925 |
| Network Prefix | 196.117.64.0/18 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 12% | 2 | 2 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 12% | 2 | 2 |
| reputation | 8% | 1 | 2 |
| geolocation | 8% | 1 | 1 |
| Overall | 9% | 8 | 9 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-07 06:27:35 UTC |
| Last Seen | 2026-10-07 10:53:08 UTC |
| Profile Built | 2026-08-29 06:37:01 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 17 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 196.117.126.168
Who owns the IP address 196.117.126.168?
196.117.126.168 is registered to ISP Orange Morocco. The address falls within the 196.112.0.0/13 network block. Registration is held at AFRINIC.
Where is 196.117.126.168 located?
Geolocation data places 196.117.126.168 in London, Casablanca-Settat, United Kingdom. The local time zone is Europe/London. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 196.117.126.168 malicious or safe?
196.117.126.168 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
Is 196.117.126.168 a VPN, proxy, or data center address?
196.117.126.168 is classified as a mobile network based on network ownership and behavioural analysis.