IPDebrief

102.0.14.42

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IPDebrief Intelligence Briefing

Target: 102.0.14.42/32

Date: 2026-07-22

Analyst Classification: Moderate Risk – Monitoring Recommended

---

## Executive Summary

IP address 102.0.14.42 presents a moderate risk profile (55/100) with no confirmed malicious activity but elevated risk indicators warranting enhanced monitoring. The IP is associated with Airtel Kenya infrastructure and operates as a web server with HTTP/HTTPS services. While the broader /24 subnet maintains a clean classification, the specific address has been detected on three DNSBLs and exhibits recent connection failure patterns.

---

## Technical Profile

AttributeValue
**Risk Score**55/100 (Moderate)
**Geolocation**Nairobi, Kenya (KE)
**ASN**36926
**BGP Prefix**102.0.14.0/24
**Network Role**Web Server
**DNS Resolution**42-14-0-102.r.airtelkenya.com
**Open Ports**80/tcp (HTTP), 443/tcp (HTTPS), 22/tcp (SSH)

---

## Threat Indicators

Abuse Confidence Score: Data not available (null)

---

## Observation History Analysis

The IP has generated 17 signal observations with the following patterns:

The lack of persistent malicious signals combined with recent connection failures suggests potential service degradation or legitimate traffic anomalies rather than coordinated attack activity.

---

## Network Neighborhood Assessment

Subnet: 102.0.14.0/24

Abuse Density: 0%

Threat Siblings: 0

Active Siblings: 1 of 5 total

Neighbor IPs in the /24 range (102.0.14.24, 102.0.14.26, 102.0.14.40, 102.0.14.230) show no elevated risk scores, indicating the risk is isolated to this specific address rather than a subnet-wide compromise.

---

## Relationships

---

## Recommended Actions

PriorityActionPlatform
**High**Increase logging verbosity and review recent activityAll
**Medium**Block IP at perimeter firewalliptables, nftables, pfSense
**Medium**Block in WAF rulesCloudflare WAF, AWS WAF
**Low**Monitor for pattern escalationSIEM/SOC

Sample Block Rules:

```bash

# iptables

iptables -A INPUT -s 102.0.14.42 -j DROP

# nftables

nft add rule inet filter input ip saddr 102.0.14.42 drop

```

---

## Intelligence Assessment

The IP exhibits moderate risk characteristics primarily due to DNSBL listings and service exposure. The absence of threat campaign correlations, persistent malicious behavior, or elevated neighborhood risk suggests limited immediate threat. However, the combination of DNSBL presence and recent connection failures warrants proactive monitoring rather than immediate blocking without further context.

Recommendation: Implement enhanced logging and monitor for escalation before definitive blocking action.

---

*This briefing is generated from IPDebrief intelligence data. All analysis is based on observed network signals and should be validated against additional threat intelligence sources.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇰🇪 Kenya
RegionNairobi County
CityNairobi
TimezoneAfrica/Nairobi
Latitude-1.28
Longitude36.82

🏢 Ownership & Registration

OrganizationUnknown
ASN—
Network Name—
CIDR Block—
RIR—
Country—
Abuse Contact—

🌐 DNS Intelligence

PTR42-14-0-102.r.airtelkenya.com
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames42-14-0-102.r.airtelkenya.com

🔐 DNS Hygiene

Hygiene Score80% (Excellent)
SPF2/2 domains
DMARC1/2 domains
FCrDNSNot verified
DNSSECValid
CAAPresent
Domains Checked2 domains

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
80httptcp—
443httpstcp—
22sshtcpBanner detected
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS36926
Network Prefix102.0.14.0/24
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
0%
00
Overall12%33
Coverage: 3/6 dimensions · Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionLow (30%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-02 04:20:17 UTC
Last Seen2026-09-18 07:06:33 UTC
Profile Built2026-08-29 11:03:40 UTC
Data FreshnessLive
Signal Types18
Total Observations23
🔍 18 signal types · 23 observations collected
This report is generated from 18+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 102.0.14.42

Where is 102.0.14.42 located?

Geolocation data places 102.0.14.42 in Nairobi, Nairobi County, Kenya. The local time zone is Africa/Nairobi. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 102.0.14.42 malicious or safe?

102.0.14.42 currently carries a high risk assessment, meaning indicators associated with malicious or abusive activity have been observed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 102.0.14.42?

The reverse DNS (PTR) record for 102.0.14.42 is 42-14-0-102.r.airtelkenya.com. This hostname is not forward-confirmed, so it should be treated as a weak signal.

What ports are open on 102.0.14.42?

Responsive ports observed on 102.0.14.42 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.

🏘️ Related IP Addresses

Nearby addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.