# IP Intelligence Briefing: 197.97.138.33/32
## Executive Summary
IP address 197.97.138.33 is classified as Moderate Risk (55/100) with no active threat indicators. The IP is geolocated to Port Elizabeth, South Africa, under ASN 3741 (ORG-DD1-AFRINIC), and currently shows no open services or malicious activity. Recommended action is increased logging and activity review.
---
## Risk Assessment
- Risk Score: 55/100 (Moderate Risk)
- Threat Indicators: None detected
- Blacklist Status: 0 entries
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Persistently Malicious: No
---
## Network & Ownership
| Field | Value |
|---|---|
| **ASN** | 3741 |
| **Organization** | Elne Kramer |
| **Netname** | ORG-DD1-AFRINIC |
| **CIDR Block** | 197.96.0.0/13 |
| **RIR** | AFRINIC |
| **Provider Score** | 0 |
| **Authority Score** | 0 |
---
## Geolocation
- Country: South Africa (ZA)
- Region: Eastern Cape
- City: Port Elizabeth
- Coordinates: -33.73°, 25.63°
- Timezone: Africa/Johannesburg
- Accuracy Radius: 800km
- Geo Consensus: Confirmed
- Geo Plausible: False (some signal discrepancy)
---
## Technical Profile
- Service Purpose: Firewalled / No Services
- Open Ports: None detected
- DNS PTR Hostnames: None
- Forward Resolution: None
- Hosted Domains: 0
- TLS Certificate: None
- Email Auth (SPF/DMARC): Not configured
- DNSSEC: Valid
- Route Stability: Not stable
- MOAS: No
---
## Control Plane Data
- Origin ASN: 3741
- BGP Prefix: 197.96.0.0/13
- Route Changes (30d): 0
- RPKI State: Not evaluated
- DNSBL Listed: 3/8 lists
- Operator Score: 0.1304 (Minimal)
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
---
## Threat History (12 Observations)
Most recent observation recorded: 2026-07-29
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Ownership Changes: 0
- Is Persistently Malicious: False
Signal history indicates consistent, non-malicious activity with no escalation trends.
---
## Network Neighborhood (197.97.138.0/24)
- Subnet Abuse Density: 0%
- Total Siblings: 0
- Active Siblings: 0
- Threat Siblings: 0
- Risk Distribution: High: 0, Medium: 0, Low: 0
No neighboring IPs identified in the /24 subnet.
---
## Relationships
- Same Network: ORG-DD1-AFRINIC (2 relationships)
- No additional related entities (hostnames, certificates, organizations) detected.
---
## Recommended Actions
Immediate
- Increase logging verbosity and review recent activity from this IP
- Severity: High (based on elevated risk score of 55/100)
Firewall Rules
| Platform | Rule |
|---|---|
| **iptables** | `iptables -A INPUT -s 197.97.138.33 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 197.97.138.33 drop` |
| **nginx** | `deny 197.97.138.33;` |
| **pfSense** | `197.97.138.33/32` |
| **Cloudflare WAF** | Block with expression: `ip.src eq 197.97.138.33` |
| **AWS WAF** | Address: `197.97.138.33/32` |
---
## Intelligence Conclusions
This IP address presents a moderate risk profile with no active threat indicators. The absence of open services, zero threat observations, and no malicious activity markers suggest benign operational use. However, the elevated risk score warrants monitoring. The IP is associated with a South African network under AFRINIC registration. No correlation with known campaigns or threat actors was identified.
Analyst Notes: Consider blocking if business policy requires strict risk mitigation. If monitoring is preferred, deploy passive observation with alert thresholds at risk score >70.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Elne Kramer |
| ASN | AS3741 |
| Network Name | ORG-DD1-AFRINIC |
| CIDR Block | 197.96.0.0/13 |
| RIR | AFRINIC |
| Country | ZA |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | lighttpd/1.4.54 |
| HTTP Title | β |
| SSH Version | SSH-2.0-dropbear T QM?q????0????x??curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-gr |
π TLS Certificate
| SANs | UBNT-FC:EC:DA:0C:96:E8 |
| Valid From | 2019-01-01T00:00:00+00:00 |
| Valid Until | 2038-01-01T00:00:00+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 6940 days |
| Serial Number | AA71338B |
| Thumbprint | E06BDBAB677D39214AB15FBAF2E04BBBE4E99B8E |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 1 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Mixed Signals (68%) β 2 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
β TLS certificate claims US but primary geo says ZA
π Observation Timeline π Live
| First Seen | 2026-07-23 01:41:16 UTC |
| Last Seen | 2026-08-10 05:11:50 UTC |
| Profile Built | 2026-08-09 23:17:37 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.