# IP Intelligence Briefing: 196.250.210.98
## Executive Summary
IP address 196.250.210.98 presents a low-risk profile with a risk score of 25/100. The IP is geolocated to Bungoma County, Kenya and is associated with ASN 327972. While the IP shows minimal threat indicators, it has one DNSBL listing flagged with high severity. The subnet abuse density is negligible (0/100), and no active services or known threat campaigns have been identified.
---
## Technical Profile
Geolocation:
- Country: Kenya (KE)
- Region: Bungoma County
- City: Bungoma
- Coordinates: 0.56°N, 34.57°E
- Timezone: Africa/Nairobi
Network Classification:
- ASN: 327972
- BGP Prefix: 196.250.210.0/24
- Origin ASN: 327972
- Network Role: Firewalled / No Services (no open ports detected)
- Not classified as cloud, CDN, proxy, Tor, VPN, or hosting infrastructure
Ownership:
- Organization: Not identified
- Abuse Contact: Not available
- Registration details: Not available
---
## Threat Intelligence
Current Threat Status:
- Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not calculated
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 1 (of 8 total DNSBL listings)
Historical Signals (9 observations):
- Most recent activity: 2026-07-30
- DNSBL activity detected with maximum severity: High
- One DNSBL listing recorded across multiple feeds
- No persistent malicious behavior observed
- Threat persistence days: 0
Campaign Correlation:
- Known Campaigns: None
- Certificate Matches: 0
- Correlated IPs: 0
---
## Neighborhood Analysis
Subnet: 196.250.210.0/24
- Abuse Density: 0 (negligible)
- Total Neighbors: 2
- Risk Distribution: 2 low-risk IPs
Identified Neighbors:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 196.250.210.37 | 25 | 50 |
| 196.250.210.85 | 25 | 50 |
No shared relationships or common infrastructure detected.
---
## Network Behavior
Services:
- Open Ports: None detected
- TLS Certificate: None
- HTTP Title: None
- Server Banner: None
DNS:
- PTR Hostnames: None
- Forward Resolution: Not confirmed
- Hosted Domains: 0
- SPF/DMARC: Not configured
Traceroute:
- Hop Count: 30
- Transit Network: Comcast
- Timed Out Hops: 18
---
## Recommended Actions
Current Risk Level: LOW
- No immediate blocking recommended
- Monitor for escalation in threat indicators
- No specific firewall rules generated at this time
Monitoring Priorities:
1. Watch for new DNSBL listings
2. Monitor subnet 196.250.210.0/24 for abuse density increases
3. Track any changes in network classification
SOC Guidance:
This IP does not warrant immediate action. The low-risk score (25/100) and minimal neighborhood abuse density suggest benign or lightly abused infrastructure. However, the single high-severity DNSBL listing warrants periodic monitoring. No correlation with known campaigns or attacker infrastructure detected.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | David Wangombe Maina |
| ASN | AS327972 |
| Network Name | 196.250.210.0 - 196.250.210.255 |
| CIDR Block | 196.250.210.0/24 |
| RIR | AFRINIC |
| Country | KE |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-26 03:08:52 UTC |
| Last Seen | 2026-07-30 06:21:36 UTC |
| Profile Built | 2026-07-30 06:32:10 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.