# IPDEBRIEF THREAT INTELLIGENCE BRIEFING
Target: 197.0.150.135/32
Classification: Low Risk / Monitoring
Date: 2026-07-25
## Executive Summary
IP 197.0.150.135 presents a low-risk profile (Risk Score: 15/100) but exhibits anomalous geolocation signals requiring monitoring. The IP is registered to ATI - Agence Tunisienne Internet (ORG-ATIA2-AFRINIC, ASN: 37705) with CIDR block 197.0.0.0/15. Critical finding: geolocation data shows conflicting signals between Tunisia (registration) and United States (resolution), indicating potential proxy behavior or data inconsistencies.
## Ownership & Network Classification
- Organization: ATI - Agence Tunisienne Internet
- ASN: 37705 (ORG-ATIA2-AFRINIC)
- CIDR Block: 197.0.0.0/15
- RIR: AFRINIC
- Registration: Tunis, Tunisia (postal code: 1002)
- Network Role: Firewalled / No Services
## Risk Assessment
| Metric | Value | Assessment |
|---|---|---|
| Risk Score | 15 | Low |
| Provider Score | 0 | N/A |
| Authority Score | 0 | N/A |
| Abuse Confidence | N/A | Not scored |
| Blacklist Count | 0 | Clean |
| Tor Exit Node | No | False |
| Known Attacker | No | False |
| Spam Source | No | False |
## Geolocation Anomaly Detected
Conflicting location data requires analyst attention:
- Registration Data: Tunis, Tunisia (AFRINIC)
- Resolution Data: New York, US (multiple sources)
- Geo Consensus: False
- Distance Anomaly: 1,760.2 km from registered location
- ICMP Validation: Blocked - unable to validate
This geolocation discrepancy (1,760 km variance) suggests either:
1. IP misconfiguration or spoofing
2. Proxy/VPN routing through US infrastructure
3. Data source inconsistency requiring correlation
## Threat Intelligence Signals
- Active Threat Indicators: None
- Campaign Associations: None detected
- Certificate Matches: 0
- Correlated IPs: 0
- Threat Persistence Days: 0
- Persistently Malicious: False
- Honeypot Hits: 0
- WAF Violations: 0
## Neighborhood Analysis
- Subnet: 197.0.150.150.0/24
- Abuse Density: 0%
- Active Siblings: 0
- Threat Siblings: 0
- High/Medium/Low Risk Neighbors: 0/0/0
The /24 subnet shows no abuse activity, suggesting this is an isolated endpoint rather than part of an attack infrastructure.
## Network Behavior & Control Plane
- Route Stable: False
- BGP Prefix: 197.0.128.0/17
- MOAS: No
- Operator Score: 0.1304 (Minimal)
- Open Ports: None detected
- DNSSEC Valid: True
- DNSBL Listed: 1 of 8 lists
## Historical Observations
Analysis of 14 observations reveals:
- First Signal: 2026-07-25T02:21:34 UTC
- Total Observations: 14
- Threat Observations: 1
- Ownership Changes: 0
- Recent Activity: Consistent Tunisia registration with US resolution conflicts
## Security Recommendations
Current Risk Level: LOW - No immediate action required
Monitoring Actions:
1. Monitor: Track geolocation consistency across sources
2. Correlate: Cross-reference with known Tunisian infrastructure
3. Alert Threshold: Investigate if risk score exceeds 50 or blacklist count increases
Firewall Rules: Not recommended at this time (risk score 15 below action threshold)
---
*Generated by IPDebrief Intelligence Platform*
*Data Source: Network observations and threat intelligence feeds*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | ATI - Agence Tunisienne Internet |
| ASN | AS37705 |
| Network Name | ORG-ATIA2-AFRINIC |
| CIDR Block | 197.0.0.0/15 |
| RIR | AFRINIC |
| Country | TN |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS37705 |
| Network Prefix | 197.0.128.0/17 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 18% | 5 | 5 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-08 19:11:19 UTC |
| Last Seen | 2026-08-27 01:42:57 UTC |
| Profile Built | 2026-08-29 06:36:10 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 19 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 197.0.150.135
Who owns the IP address 197.0.150.135?
197.0.150.135 is registered to ATI - Agence Tunisienne Internet. The address falls within the 197.0.0.0/15 network block. Registration is held at AFRINIC.
Where is 197.0.150.135 located?
Geolocation data places 197.0.150.135 in New York, US-NY, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 197.0.150.135 malicious or safe?
197.0.150.135 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.