# IP Intelligence Briefing: 196.156.139.113/32
## Executive Summary
IP address 196.156.139.113 presents a moderate risk profile (Risk Score: 50) with no active threat indicators. The address is geolocated to Cairo, Egypt and operates under ASN 36935 within BGP prefix 196.156.136.0/22. No open services or known malicious activity detected, though the IP appears on 2 of 8 DNSBL lists and exhibits route instability.
## Network Characteristics
- Geolocation: Egypt (Cairo Governorate, Cairo)
- ASN: 36935
- BGP Prefix: 196.156.136.0/22
- Network Role: Firewalled / No Services
- DNS Resolution: No PTR records, forward resolution unconfirmed
- Email Authentication: No SPF/DMARC records
## Threat Assessment
Risk Score: 50 (Moderate Risk)
Threat Indicators:
- Blacklist Count: 0 (traditional blacklists)
- DNSBL Listed: 2 of 8 lists
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Active Attacker: No
- Known Campaigns: None
Behavioral Signals:
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: 0
## Control Plane Analysis
- Route Stability: False (unstable routing)
- RPKI State: Not verified
- DNSSEC Valid: Yes
- Route Changes (30d): 0
- Operator Score: 0.1304 (Minimal)
## Neighborhood Analysis
- Subnet: 196.156.139.0/24
- Abuse Density: 0
- Threat Siblings: 0
- Active Siblings: 0
## Observation History
Seven observations recorded. Recent signals include:
- Geolocation confirmed to Cairo, Egypt (2026-07-30)
- DNSSEC validation confirmed (2026-07-30)
- Routing/ownership signals with low confidence (0.12)
- DNSBL listing activity observed (2026-07-30)
## Relationship Graph
No relationships detected to subnets, hostnames, organizations, or certificates.
## Recommended Security Actions
Based on the moderate risk profile, the following firewall rules are recommended:
iptables:
```
iptables -A INPUT -s 196.156.139.113 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 196.156.139.113 drop
```
nginx:
```
deny 196.156.139.113;
```
pfSense:
```
196.156.139.113/32
```
Cloudflare WAF:
Block IP 196.156.139.113 with expression `ip.src eq 196.156.139.113`
AWS WAF:
Add IPSet entry `196.156.139.113/32`
## Analyst Notes
While the risk score is moderate (50), the IP demonstrates no active malicious behavior. The primary risk factors are:
1. Presence on 2 DNSBL lists
2. Route instability (isRouteStable: false)
3. Low operator score (0.1304)
No threat indicators suggest active compromise or abuse. The recommendation to block is based on the aggregate risk score rather than confirmed malicious activity. SOC teams may consider allowing traffic with monitoring if business requirements dictate, given the absence of behavioral threat signals.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Wafaa Salah |
| ASN | AS36935 |
| Network Name | 196.144.0.0 - 196.159.255.255 |
| CIDR Block | 196.144.0.0/12 |
| RIR | AFRINIC |
| Country | EG |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-28 22:22:13 UTC |
| Last Seen | 2026-07-30 19:00:43 UTC |
| Profile Built | 2026-07-30 19:10:46 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.