IPDebrief

196.203.63.80

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# INTELLIGENCE BRIEFING: 196.203.63.80/32

Classification: LOW RISK

Risk Score: 25/100

Date of Analysis: 2026-07-28

## EXECUTIVE SUMMARY

IP address 196.203.63.80 is registered to ATI - Agence Tunisienne Internet (ASN 37693) under AFRINIC. The IP presents a low risk profile with limited threat indicators. Current observation data indicates firewalled status with no active services. Geolocation data shows conflicting signals between Tunisian (TN) and US (New York) sources, requiring further validation.

## OWNERSHIP AND ATTRIBUTION

AttributeValue
**Organization**ATI - Agence Tunisienne Internet
**ASN**37693
**CIDR Block**196.203.56.0/21
**RIR**AFRINIC
**Abuse Contact**Not Provided

The IP belongs to a Tunisian telecommunications provider with no known abuse history. Network classification indicates firewalled infrastructure with no exposed services.

## GEOLOCATION ANALYSIS

Conflicting geolocation signals observed across multiple data sources:

This discrepancy warrants monitoring. The AFRINIC registration strongly indicates Tunisian ownership, while the US signal may represent routing anomalies or CDN placement.

## THREAT INTELLIGENCE

IndicatorStatus
**Blacklist Count**1 (DNSBL listed)
**Known Attacker**No
**Spam Source**No
**Tor Exit Node**No
**Known Campaigns**None
**Abuse Confidence Score**Not Calculated

Control plane analysis reveals 1 DNSBL listing with high severity among 8 total lists. RPKI state is null, and the route shows instability (isRouteStable: false).

## NETWORK BEHAVIOR

No open services or banner information available. The IP appears to be used for upstream infrastructure rather than direct host services.

## TEMPORAL ANALYSIS

Recent history shows 13 observations with consistent ownership and no significant threat pattern changes over time.

## NEIGHBORHOOD ANALYSIS

Subnet: 196.203.63.0/24

No neighboring IPs detected in the /24 subnet. The absence of sibling activity suggests isolated infrastructure rather than a cluster.

## RELATIONSHIP GRAPH

Limited relationship data with only the originating network organization identified.

## RECOMMENDED ACTIONS

Action TypeRecommendationPriority
**Monitoring**Continue passive observationMedium
**Blocking**No action requiredLow
**Investigation**Verify geolocation discrepancyMedium
**DNSBL Check**Review DNSBL listing detailsLow

## SOC ANALYST NOTES

1. Low Immediate Threat: The IP maintains a low risk score (25) with no active threat indicators requiring immediate action.

2. Geolocation Discrepancy: The conflict between US and Tunisian geolocation data should be flagged for validation. This may indicate:

- Misconfigured routing

- CDN edge node placement

- Data source inconsistency

3. DNSBL Listing: One high-severity DNSBL listing exists. Review the specific blacklist and determine if it relates to the IP or associated infrastructure.

4. Route Instability: The BGP prefix shows route instability. Monitor for potential network renumbering or infrastructure changes.

5. No Active Services: With no open ports or services, the IP does not pose immediate exploitation risk.

---

Intelligence Generated: 2026-07-28

Data Sources: IPDebrief Intelligence Platform

Confidence Level: Medium (geolocation inconsistency)

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇺🇸 United States
RegionUS-NY
CityNew York
TimezoneAmerica/New_York
Latitude—
Longitude—

🏢 Ownership & Registration

OrganizationATI - Agence Tunisienne Internet
ASNAS37693
Network NameORG-ATIA2-AFRINIC
CIDR Block196.203.56.0/21
RIRAFRINIC
CountryTN
Abuse Contact—

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)

🔐 DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCPresent
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
80httptcp—
443httpstcp—
22sshtcpBanner detected
8080http-alttcp—
Closed Ports25, 3389, 8443 (4 open / 7 scanned)
ServerWeb server detected
HTTP Title—

🔐 TLS Certificate

An expired certificate for CN=streaming.toutech.net was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.
🔒
CN=streaming.toutech.net
Issued by CN=R12, O=Let's Encrypt, C=US
Self-signed: No
SANsstreaming.toutech.net
Valid From2026-03-19T14:52:30+00:00
Valid Until2026-06-17T14:52:29+00:00 (expired)
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period89 days

🛡️ Public Network Snapshot

Origin ASNAS37693
Network Prefix196.203.62.0/23
Route mappingFound
HSTSNot detected
CSPNot detected
HTTP/2Not detected

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
23%
24
routing
8%
11
services
17%
23
ownership
12%
22
reputation
14%
13
geolocation
12%
22
Overall14%1015
Coverage: 2/6 dimensions · Data sufficiency: partial
Data CoherenceMostly Consistent (80%) — 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: Tunisia, TN, US

📅 Observation Timeline 🔄 Live

First Seen2026-07-15 22:23:48 UTC
Last Seen2026-09-01 03:20:29 UTC
Profile Built2026-09-01 03:27:43 UTC
Data FreshnessLive
Signal Types21
Total Observations28
🔍 21 signal types · 28 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 196.203.63.80

Who owns the IP address 196.203.63.80?

196.203.63.80 is registered to ATI - Agence Tunisienne Internet. The address falls within the 196.203.56.0/21 network block. Registration is held at AFRINIC.

Where is 196.203.63.80 located?

Geolocation data places 196.203.63.80 in New York, US-NY, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 196.203.63.80 malicious or safe?

196.203.63.80 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.

What ports are open on 196.203.63.80?

Responsive ports observed on 196.203.63.80 include 80, 443, 22, 8080. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.