# IP Intelligence Briefing: 196.251.121.45/32
## Executive Summary
IP address 196.251.121.45 is classified as Low Risk (riskScore: 0) but exhibits contradictory intelligence signals including recent high-severity blacklist listings and geolocation inconsistencies. The IP operates in the 196.251.121.0/24 subnet with 7.7% abuse density and contains one high-risk sibling IP (196.251.121.106, riskScore: 80). No active services or open ports detected.
## Current Profile
Risk Assessment: Low Risk (riskScore: 0) | Reputation: Low Risk
Geolocation: Boston, US-MA (profile) / South Africa (recent history) - CONFLICTING DATA
Network: ASN 205759 (GHOSTYNETWORKS - Ghosty Networks LLC) via team-cymru-dns
Services: None detected (firewalled/no services)
DNS: PTR hostnames: None | Forward resolution: 0 hosts
Control Plane: Route stability flagged as false; 0 route changes in 30-day period
## Threat Indicators
Blacklist Status: 1 active listing (high severity) as of 2026-07-28
Known Campaigns: None identified
Threat Feeds: No active threat indicators
Behavior: Not an active attacker; 0 honeypot hits; 0 WAF violations
## Historical Analysis (12 observations)
- Geolocation Conflicts: Recent probes indicate South Africa coordinates (SC, -4.5833, 55.6667) conflicting with profile's US-MA Boston location
- Blacklist Activity: Single high-severity listing detected with 8 total list associations
- DNSSEC: Valid
- Ownership Changes: 0 changes observed
- Threat Persistence: 0 days (not persistently malicious)
## Network Neighborhood Analysis (196.251.121.0/24)
Subnet Abuse Density: 7.7% (0.077)
Total Siblings: 13 IPs
Risk Distribution: 1 high-risk, 4 medium-risk, 8 low-risk
High-Risk Neighbors Requiring Attention:
- 196.251.121.106 (riskScore: 80, authorityScore: 50)
- 196.251.121.101 (riskScore: 55, authorityScore: 50)
- 196.251.121.23, .27, .106, .126, .130 (riskScore: 50)
## Intelligence Assessment & Recommendations
Primary Concern: The ASN designation "GHOSTYNETWORKS" combined with high-severity blacklist activity and geolocation conflicts suggests potential malicious network operations, despite low overall risk scoring.
Key Indicators for SOC Monitoring:
1. Geolocation inconsistency between profile and recent observations may indicate spoofing or multi-region abuse
2. High-severity blacklist listing requires investigation despite 0 current risk score
3. Subnet abuse density (7.7%) with 1 high-risk neighbor warrants monitoring of related IPs
4. No relationship graph data limits correlation capabilities
Recommended Actions:
- Monitor 196.251.121.106 (riskScore: 80) for confirmed malicious activity
- Investigate blacklist listing source and reason for high severity classification
- Consider blocking subnet 196.251.121.0/24 if business traffic patterns don't justify risk
- Implement geolocation validation rules to flag conflicting data sources
- Monitor for any service openings on this previously firewalled IP
Confidence Level: Medium (data inconsistencies present; 0 current services detected reduces immediate threat)
Classification: Standard Monitoring Required
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Qazi Sikandar Raza |
| ASN | AS205759 |
| Network Name | 196.251.121.0 - 196.251.121.255 |
| CIDR Block | 196.251.121.0/24 |
| RIR | AFRINIC |
| Country | SC |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS205759 |
| Network Prefix | 196.251.121.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 8% | 2 | 2 |
| Data Coherence | Mixed Signals (60%) — 2 contradiction(s) |
| Attribution | Very Low (20%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
⚠ Geo sources disagree on country: SC, US
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-15 22:23:48 UTC |
| Last Seen | 2026-09-01 00:16:09 UTC |
| Profile Built | 2026-08-30 20:12:24 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 18 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 196.251.121.45
Who owns the IP address 196.251.121.45?
196.251.121.45 is registered to Qazi Sikandar Raza. The address falls within the 196.251.121.0/24 network block. Registration is held at AFRINIC.
Where is 196.251.121.45 located?
Geolocation data places 196.251.121.45 in Boston, US-MA, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 196.251.121.45 malicious or safe?
196.251.121.45 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 196.251.121.45?
Responsive ports observed on 196.251.121.45 include 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.