## IP Intelligence Briefing: 102.0.35.78
Classification: Low Risk (Score: 25/100)
---
Executive Summary
IP 102.0.35.78 is classified as a low-risk residential endpoint located in Nakuru, Kenya. The address operates as a single-service host with SSH access enabled and no evidence of malicious activity, blacklisting, or threat campaign association. The subnet exhibits clean classification with no active threat siblings.
---
Ownership and Geolocation
- ASN: 36926
- Organization: John Kiama
- Network Block: 102.0.0.0 - 102.3.255.255 (/14)
- RIR: AfriNIC
- Country: Kenya (KE)
- City: Nakuru
- Timezone: Africa/Nairobi
- Geographic Validation: Plausible (6,418.1 km distance from probe location; 221–227 ms RTT)
---
Network Role and Services
- Type: Single-Service Host
- Open Ports: TCP/22 (SSH)
- SSH Banner: SSH-2.0-ROSSSH
- DNS Resolution: 78-35-0-102.r.airtelkenya.com
- Domain: airtelkenya.com
- Email Authentication: SPF record present; DMARC not configured
- TLS/HTTP: No web services detected; no TLS certificates
---
Threat Indicators
- Blacklist Status: Clean (0 entries)
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Association: None detected
- Threat Persistence: No persistent malicious activity observed
---
Neighborhood Analysis
- Subnet: 102.0.35.0/24
- Abuse Density: 0% (Clean classification)
- Active Threat Siblings: 0
- Total Siblings: 1
- Risk Distribution: No high or medium-risk neighbors identified
---
Relationship Graph
- Same Network Associations: Multiple entries linking to 102.0.0.0 - 102.3.255.255
- DNS Associations: 4 entries resolving to 78-35-0-102.r.airtelkenya.com
- No Cross-Subnet Threat Correlations: None detected
---
Historical Observation
- Total Observations: 18 signals
- Most Recent Activity: 2026-07-28
- Ownership Stability: 0 changes recorded
- Threat Observation Count: 0
- Signal Types: Geovalidation, port scanning, DNS resolution, network registration
---
Recommended Actions
Based on the low-risk profile and absence of actionable threat indicators, no immediate firewall or mitigation rules are recommended. The IP exhibits characteristics consistent with legitimate residential infrastructure.
Monitoring Priority: Routine
Block Recommendation: No
Allow Recommendation: Yes (with standard network policies)
---
Analyst Notes
This IP represents a standard residential endpoint with no adversarial signals. The presence of a single open SSH port and lack of web services is consistent with personal or small-scale residential usage. No correlation with known threat actors or abuse campaigns was established.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | John Kiama |
| ASN | AS36926 |
| Network Name | 102.0.0.0 - 102.3.255.255 |
| CIDR Block | 102.0.0.0/14 |
| RIR | AFRINIC |
| Country | KE |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR | 78-35-0-102.r.airtelkenya.com |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 78-35-0-102.r.airtelkenya.com |
🔐 DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | 2/2 domains |
| DMARC | 1/2 domains |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
| Domains Checked | 2 domains |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS36926 |
| Network Prefix | 102.0.35.0/24 |
| Route mapping | Found |
| Certificates in transparency logs | 0 certificates |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-17 23:20:44 UTC |
| Last Seen | 2026-09-01 01:26:44 UTC |
| Profile Built | 2026-09-01 01:29:35 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 26 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 102.0.35.78
Who owns the IP address 102.0.35.78?
102.0.35.78 is registered to John Kiama. The address falls within the 102.0.0.0/14 network block. Registration is held at AFRINIC.
Where is 102.0.35.78 located?
Geolocation data places 102.0.35.78 in Nakuru, 31, Kenya. The local time zone is Africa/Nairobi. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 102.0.35.78 malicious or safe?
102.0.35.78 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 102.0.35.78?
The reverse DNS (PTR) record for 102.0.35.78 is 78-35-0-102.r.airtelkenya.com. This hostname is not forward-confirmed, so it should be treated as a weak signal.
What ports are open on 102.0.35.78?
Responsive ports observed on 102.0.35.78 include 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.