# INTELLIGENCE BRIEFING: 196.203.63.80/32
Classification: LOW RISK
Risk Score: 25/100
Date of Analysis: 2026-07-28
## EXECUTIVE SUMMARY
IP address 196.203.63.80 is registered to ATI - Agence Tunisienne Internet (ASN 37693) under AFRINIC. The IP presents a low risk profile with limited threat indicators. Current observation data indicates firewalled status with no active services. Geolocation data shows conflicting signals between Tunisian (TN) and US (New York) sources, requiring further validation.
## OWNERSHIP AND ATTRIBUTION
| Attribute | Value |
|---|---|
| **Organization** | ATI - Agence Tunisienne Internet |
| **ASN** | 37693 |
| **CIDR Block** | 196.203.56.0/21 |
| **RIR** | AFRINIC |
| **Abuse Contact** | Not Provided |
The IP belongs to a Tunisian telecommunications provider with no known abuse history. Network classification indicates firewalled infrastructure with no exposed services.
## GEOLOCATION ANALYSIS
Conflicting geolocation signals observed across multiple data sources:
- Primary Signal: New York, US (US-NY)
- Secondary Signal: Tunis, TN (AFRINIC registration data)
- GeoValidation Status: Inconsistent (geoConsensus: false)
This discrepancy warrants monitoring. The AFRINIC registration strongly indicates Tunisian ownership, while the US signal may represent routing anomalies or CDN placement.
## THREAT INTELLIGENCE
| Indicator | Status |
|---|---|
| **Blacklist Count** | 1 (DNSBL listed) |
| **Known Attacker** | No |
| **Spam Source** | No |
| **Tor Exit Node** | No |
| **Known Campaigns** | None |
| **Abuse Confidence Score** | Not Calculated |
Control plane analysis reveals 1 DNSBL listing with high severity among 8 total lists. RPKI state is null, and the route shows instability (isRouteStable: false).
## NETWORK BEHAVIOR
- Service Status: Firewalled / No Services
- Open Ports: None detected
- TLS Certificates: None
- HTTP Services: None
- DNS Records: 0 forward confirmations
- PTR Hostnames: None
No open services or banner information available. The IP appears to be used for upstream infrastructure rather than direct host services.
## TEMPORAL ANALYSIS
- Threat Observations: 1
- Threat Persistence: Not persistently malicious
- Ownership Changes: 0 (stable)
- Average Ownership Days: Unavailable
- Observation Count: 13 total signals
Recent history shows 13 observations with consistent ownership and no significant threat pattern changes over time.
## NEIGHBORHOOD ANALYSIS
Subnet: 196.203.63.0/24
- Total Siblings: 0
- Active Siblings: 0
- Threat Siblings: 0
- Abuse Density: 0%
No neighboring IPs detected in the /24 subnet. The absence of sibling activity suggests isolated infrastructure rather than a cluster.
## RELATIONSHIP GRAPH
- Same Network: ORG-ATIA2-AFRINIC
- Related Hostnames: None
- Organizations: ATI - Agence Tunisienne Internet
- Certificates: None
Limited relationship data with only the originating network organization identified.
## RECOMMENDED ACTIONS
| Action Type | Recommendation | Priority |
|---|---|---|
| **Monitoring** | Continue passive observation | Medium |
| **Blocking** | No action required | Low |
| **Investigation** | Verify geolocation discrepancy | Medium |
| **DNSBL Check** | Review DNSBL listing details | Low |
## SOC ANALYST NOTES
1. Low Immediate Threat: The IP maintains a low risk score (25) with no active threat indicators requiring immediate action.
2. Geolocation Discrepancy: The conflict between US and Tunisian geolocation data should be flagged for validation. This may indicate:
- Misconfigured routing
- CDN edge node placement
- Data source inconsistency
3. DNSBL Listing: One high-severity DNSBL listing exists. Review the specific blacklist and determine if it relates to the IP or associated infrastructure.
4. Route Instability: The BGP prefix shows route instability. Monitor for potential network renumbering or infrastructure changes.
5. No Active Services: With no open ports or services, the IP does not pose immediate exploitation risk.
---
Intelligence Generated: 2026-07-28
Data Sources: IPDebrief Intelligence Platform
Confidence Level: Medium (geolocation inconsistency)
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | ATI - Agence Tunisienne Internet |
| ASN | AS37693 |
| Network Name | ORG-ATIA2-AFRINIC |
| CIDR Block | 196.203.56.0/21 |
| RIR | AFRINIC |
| Country | TN |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| 8080 | http-alt | tcp | — |
| Closed Ports | 25, 3389, 8443 (4 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
CN=streaming.toutech.net was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.| SANs | streaming.toutech.net |
| Valid From | 2026-03-19T14:52:30+00:00 |
| Valid Until | 2026-06-17T14:52:29+00:00 (expired) |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
🛡️ Public Network Snapshot
| Origin ASN | AS37693 |
| Network Prefix | 196.203.62.0/23 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 23% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 17% | 2 | 3 |
| ownership | 12% | 2 | 2 |
| reputation | 14% | 1 | 3 |
| geolocation | 12% | 2 | 2 |
| Overall | 14% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-15 22:23:48 UTC |
| Last Seen | 2026-09-01 03:20:29 UTC |
| Profile Built | 2026-09-01 03:27:43 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 28 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 196.203.63.80
Who owns the IP address 196.203.63.80?
196.203.63.80 is registered to ATI - Agence Tunisienne Internet. The address falls within the 196.203.56.0/21 network block. Registration is held at AFRINIC.
Where is 196.203.63.80 located?
Geolocation data places 196.203.63.80 in New York, US-NY, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 196.203.63.80 malicious or safe?
196.203.63.80 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 196.203.63.80?
Responsive ports observed on 196.203.63.80 include 80, 443, 22, 8080. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.