# IP INTELLIGENCE BRIEFING
Target: 196.171.30.121/32
Classification: LOW RISK / DEFENSIVE MONITORING
Date: 2026-07-22
## EXECUTIVE SUMMARY
IP address 196.171.30.121 is classified as low risk with a risk score of 0. The address shows no active threat indicators, no blacklist presence, and no open services. The IP is associated with a legitimate network allocation and demonstrates stable ownership characteristics. No immediate blocking or mitigation actions are recommended based on current data.
## NETWORK OWNERSHIP & REGISTRATION
- ASN: 24691
- Organization: GNALOU Mazama Esso
- CIDR Block: 196.170.0.0/15
- RIR: AFRINIC
- Netname: 196.170.0.0 - 196.171.255.255
- Abuse Contact: Not available
The IP falls within a registered network block with minimal operator score (0.1304), indicating limited infrastructure activity.
## GEOLOCATION ANALYSIS
- Country: United Kingdom (GB)
- Region: Maritime
- City: London
- Coordinates: 6.1316°N, 1.2240°E
- Distance from Probe: 5,174 km
- Minimum RTT: 103.5 ms
Geolocation data shows consensus between multiple sources (geoSourceCount: 2), though geoConsensus is flagged as false. The geographic positioning is plausible for the claimed origin.
## THREAT INTELLIGENCE PROFILE
- Risk Score: 0 (Low Risk)
- Abuse Confidence Score: Not applicable
- Blacklist Count: 0
- Threat Feeds: None detected
- Is Known Attacker: False
- Is Spam Source: False
- Is Tor Exit Node: False
Threat Indicators: Empty — No indicators of compromise detected.
## NETWORK BEHAVIOR & SERVICES
- Open Ports: None detected
- DNS Resolution: Not configured
- Email Authentication: No SPF/DMARC records
- Service Purpose: Firewalled / No Services
- Cloud/Proxy Status: Not identified as cloud, CDN, VPN, proxy, or hosting infrastructure
The IP shows no active network services and is firewalled, indicating minimal exposure to external scanning or exploitation attempts.
## CONTROL PLANE ANALYSIS
- BGP Prefix: 196.171.16.0/20
- Route Stability: Unstable (isRouteStable: false)
- Route Changes (30d): 0
- RPKI State: Not validated
- IRR Consistency: Not validated
- DNSSEC: Valid
- DNSBL Listings: 0 of 8 total lists
## NEIGHBORHOOD ANALYSIS
- Subnet: 196.171.30.121/24
- Abuse Density: 0 (Clean)
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 0
The /24 subnet shows zero abuse activity and no neighboring IPs with threat indicators.
## OBSERVATION HISTORY
Total Observations: 14
Status: Consistent clean classification across all observation periods.
Recent observations indicate:
- Classification: Clean (abuse density: 0)
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
The IP has demonstrated persistent benign behavior with no escalation in threat posture.
## RELATIONSHIP GRAPH
- Network Relationships: 3 entries to same network blocks (196.170.0.0 - 196.171.255.255)
- Associated Hostnames: None
- Certificates: None
- Organizations: None beyond network registration
## RECOMMENDED ACTIONS
Status: No action required.
The IP address presents no immediate security concerns. Standard logging and monitoring are sufficient. No firewall rules, WAF configurations, or blocking recommendations are warranted at this time.
## SOC ANALYST NOTES
- Monitor for any service activation or port opening
- Review geolocation discrepancy if traffic patterns suggest otherwise
- No correlation with known campaigns or threat actors
- Subnet-level analysis confirms clean neighborhood context
---
*Report generated from IPDebrief intelligence data. All data points sourced from live IPDebrief API queries.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | GNALOU Mazama Esso |
| ASN | AS24691 |
| Network Name | 196.170.0.0 - 196.171.255.255 |
| CIDR Block | 196.170.0.0/15 |
| RIR | AFRINIC |
| Country | TG |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS24691 |
| Network Prefix | 196.171.16.0/20 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 20% | 2 | 2 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 12% | 2 | 2 |
| reputation | 8% | 1 | 2 |
| geolocation | 12% | 2 | 2 |
| Overall | 12% | 10 | 11 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-02 04:21:30 UTC |
| Last Seen | 2026-08-24 17:53:25 UTC |
| Profile Built | 2026-08-29 09:32:23 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 19 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 196.171.30.121
Who owns the IP address 196.171.30.121?
196.171.30.121 is registered to GNALOU Mazama Esso. The address falls within the 196.170.0.0/15 network block. Registration is held at AFRINIC.
Where is 196.171.30.121 located?
Geolocation data places 196.171.30.121 in London, Maritime, United Kingdom. The local time zone is Europe/London. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 196.171.30.121 malicious or safe?
196.171.30.121 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.