IPDebrief

197.157.192.149

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

Threat Intelligence Briefing: IP 197.157.192.149/32

Summary:

IP address 197.157.192.149/32 was observed during a recent investigation into network traffic anomalies. The intelligence gathered provides a detailed profile, historical observations, and neighborhood context that may aid SOC analysts in identifying potential security threats or anomalies associated with this IP address.

Profile:

Observation History:

Relationships:

Neighborhood Data:

Actionable Insights:

1. Enhanced Monitoring: Implement enhanced monitoring for traffic originating from or directed to 197.157.192.149, particularly during identified peak activity periods.

2. Traffic Analysis: Conduct a deeper analysis of outbound traffic to detect any anomalies that could indicate data exfiltration or unauthorized communications with known malicious entities.

3. Domain Blacklisting: Consider blacklisting or closely scrutinizing domains associated with this IP address that have been flagged for malicious activity.

4. Neighborhood Scrutiny: Increase vigilance on neighboring IP addresses that share similar risk indicators, as they may be part of a larger coordinated threat.

5. Incident Response Preparedness: Prepare incident response plans to quickly address any confirmed malicious activities associated with this IP and its neighborhood.

This intelligence briefing provides a comprehensive overview of the potential risks and actions associated with IP address 197.157.192.149/32, enabling SOC analysts to make informed decisions in their defensive security operations.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐ŸŒ BI
RegionKY
CityKayanza
Timezoneโ€”
Latitude-2.92
Longitude29.62

๐Ÿข Ownership & Registration

OrganizationWaleed Yislam
ASNAS37429
Network NameORG-SSB1-AFRINIC
CIDR Block197.157.192.0/22
RIRAFRINIC
CountryBI
Abuse Contactโ€”

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
19%
22
routing
13%
11
services
13%
11
ownership
19%
22
reputation
13%
12
geolocation
13%
11
Overall15%89
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-14 19:28:41 UTC
Last Seen2026-06-09 14:17:58 UTC
Profile Built2026-06-07 08:34:06 UTC
Data FreshnessLive
Signal Types16
Total Observations16
๐Ÿ” 16 signal types ยท 16 observations collected
This report is generated from 16+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.