IPDebrief

41.0.125.148

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target IP: 41.0.125.148/32

Report Date: July 27, 2026

Classification: Low Risk

---

## EXECUTIVE SUMMARY

IP address 41.0.125.148 is classified as low risk with a risk score of 25/100. The address belongs to Vodacom mobile network infrastructure in the 41.0.0.0/16 CIDR block. No active threat indicators were detected, and the IP has a clean neighborhood classification with zero abuse density in its /24 subnet.

---

## NETWORK OWNERSHIP & ATTRIBUTION

---

## GEOLOCATION ANALYSIS

Geolocation data presents conflicting sources:

This discrepancy suggests the IP may be routed through multiple international backbone points or geolocation databases contain conflicting assignments.

---

## THREAT INDICATORS ASSESSMENT

IndicatorStatus
Risk Score25/100 (Low)
Known AttackerNo
Tor Exit NodeNo
Spam SourceNo
Blacklist Count0
DNSBL Listings1 of 8 (minimal)
Threat FeedsNone
Known CampaignsNone

Threat Indicators: None detected.

---

## NETWORK BEHAVIOR & SERVICES

---

## DNS ANALYSIS

---

## NEIGHBORHOOD ANALYSIS

---

## RELATIONSHIP MAPPING

Identified relationships include:

1. Same Network: 41.0.0.0 - 41.0.255.255

2. DNS Association: vc-vb-41-0-125-148.ens.vodacom.co.za (listed twice)

No external entity relationships detected.

---

## OBSERVATION HISTORY

Total observations: 15

Recent Signals (July 27, 2026):

Temporal Analysis:

---

## CONTROL PLANE DATA

---

## RECOMMENDED ACTIONS

Current Risk Assessment: Low Risk (Score: 25)

Firewall Recommendations: None required at this time

SOC Analyst Guidance:

1. No immediate blocking recommended – IP shows no malicious activity

2. Monitor geolocation consistency – Conflicting GB/ZA data warrants periodic re-validation

3. Standard mobile traffic classification – Treat as Vodacom mobile infrastructure traffic

4. DNSBL monitoring – One DNSBL listing detected; monitor for escalation

5. Baseline behavior – No open services; expect firewalled behavior typical of mobile carrier IP

---

## RISK CONCLUSION

IP 41.0.125.148 is a low-risk mobile carrier address belonging to Vodacom's infrastructure. The address demonstrates no threat indicators, maintains a clean neighborhood classification, and shows stable operational characteristics. SOC teams should classify this traffic as legitimate mobile infrastructure with standard monitoring protocols.

Threat Level: LOW

Recommendation: ALLOW with standard logging

---

*Report generated using IPDebrief intelligence platform. All data sourced from live network observations and threat intelligence feeds.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇿🇦 South Africa
RegionGauteng
CityJohannesburg
TimezoneAfrica/Johannesburg
Latitude-26.19
Longitude28.08

🏢 Ownership & Registration

OrganizationJacques Hendricks
ASNAS36994
Network Name41.0.0.0 - 41.0.255.255
CIDR Block41.0.0.0/16
RIRAFRINIC
CountryZA
Abuse Contact—

🌐 DNS Intelligence

PTRvc-vb-41-0-125-148.ens.vodacom.co.za
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesvc-vb-41-0-125-148.ens.vodacom.co.za

🔐 DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCPresent
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureMobile
Service PurposeFirewalled / No Services
Network TierUnknown — Insufficient routing data to classify
Mobile

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS36994
Network Prefix41.0.0.0/16
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
23
routing
8%
11
services
12%
22
ownership
12%
22
reputation
8%
12
geolocation
12%
22
Overall13%1012
Coverage: 3/6 dimensions · Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-13 09:17:40 UTC
Last Seen2026-09-02 19:28:50 UTC
Profile Built2026-09-01 01:49:44 UTC
Data FreshnessLive
Signal Types21
Total Observations26
🔍 21 signal types · 26 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 41.0.125.148

Who owns the IP address 41.0.125.148?

41.0.125.148 is registered to Jacques Hendricks. The address falls within the 41.0.0.0/16 network block. Registration is held at AFRINIC.

Where is 41.0.125.148 located?

Geolocation data places 41.0.125.148 in Johannesburg, Gauteng, South Africa. The local time zone is Africa/Johannesburg. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 41.0.125.148 malicious or safe?

41.0.125.148 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 41.0.125.148?

The reverse DNS (PTR) record for 41.0.125.148 is vc-vb-41-0-125-148.ens.vodacom.co.za. This hostname is not forward-confirmed, so it should be treated as a weak signal.

Is 41.0.125.148 a VPN, proxy, or data center address?

41.0.125.148 is classified as a mobile network based on network ownership and behavioural analysis.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.