# IP Intelligence Briefing: 41.138.89.216/32
Classification: MODERATE RISK
Date: July 29, 2026
Prepared For: SOC Operations Team
---
## Executive Summary
IP address 41.138.89.216 presents a moderate risk profile (score: 55/100) associated with ETISALAT BENIN SA (ASN: 37136). The IP operates within a firewalled subnet with no active services. Geographic validation conflicts exist between reported locations in Cotonou, Benin and London, UK, with 5,138.6km distance discrepancy. The IP demonstrates low threat activity with zero blacklist hits and no observed malicious behavior in historical records.
---
## Network Ownership & Infrastructure
- Organization: ETISALAT BENIN SA
- ASN: AS37136 (African Network Information Center)
- CIDR Block: 41.138.89.0/24
- RIR Registry: AFRINIC
- Abuse Contact: Not publicly listed
- Registration: No registration date data available
The subnet shows no inheritance of risk from neighboring addresses and maintains zero abuse density within the /24 range. Control plane analysis indicates route stability issues, with three DNSBL listings recorded across eight total lists.
---
## Geolocation Analysis
Geographic data presents conflicting signals:
- Primary Location: London, United Kingdom (GB)
- Secondary Location: Cotonou, Benin (BJ)
- Geographic Consensus: FALSE (3 sources, disagreement detected)
- Geographic Plausibility: TRUE
- Distance Discrepancy: 5,138.6km between claimed and inferred coordinates
- Validation Status: ICMP blocked - unable to validate
This geographic inconsistency warrants continued monitoring for potential spoofing or misattribution.
---
## Threat Indicators Assessment
| Indicator | Status |
|---|---|
| Known Attacker | No |
| Tor Exit Node | No |
| Spam Source | No |
| Blacklist Count | 0 |
| Abuse Confidence Score | Not calculated |
| Known Campaigns | None |
| Threat Feeds | Empty |
No malicious threat indicators were detected across threat feeds or reputation sources. The IP maintains a clean threat profile with zero observed attacks.
---
## Network Behavior & Services
- Service Status: Firewalled / No Services
- Open Ports: None detected
- DNS Resolution: No PTR records, no forward resolution
- Hosted Domains: None
- Email Reputation: No data available
- TLS Certificates: None
- HTTP Services: None detected
The IP shows no active service exposure and appears to be in a dormant or non-public-facing state.
---
## Historical Observation Trends
Total Observations: 13 signals
Observation Window: Recent activity from July 29, 2026
Temporal Metrics:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Persistently Malicious: No
- Operator Score: 0.1304 (Minimal)
Historical analysis indicates stable ownership with no threat persistence patterns. The IP has demonstrated low operator activity with minimal signals across monitoring windows.
---
## Network Relationships
- Connected Entities: 1
- Relationship Type: Same Network (41.138.89.0/24)
The IP maintains only network-level relationships with no organizational, hostname, or certificate associations.
---
## Recommended Actions
Based on the moderate risk profile and absence of active threat indicators:
Immediate Actions:
1. No immediate blocking required - maintain monitoring
2. Consider geo-blocking if traffic originates from unexpected regions
3. Monitor for emergence of open services or port scanning activity
Long-term Monitoring:
1. Track geographic validation conflicts for potential spoofing
2. Monitor DNSBL listing status changes
3. Watch for any service activation within the subnet
4. Review any new threat feed associations
Firewall Rules:
No specific firewall rules recommended at this time due to lack of active threat indicators. Standard rate limiting may be applied if traffic anomalies emerge.
---
Status: ACTIVE MONITORING
Next Review: Periodic review recommended pending any service activation or geographic anomalies
*Report generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | ETISALAT BENIN SA |
| ASN | AS37136 |
| Network Name | 41.138.89.0 - 41.138.89.255 |
| CIDR Block | 41.138.89.0/24 |
| RIR | AFRINIC |
| Country | BJ |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS37136 |
| Network Prefix | 41.138.89.0/24 |
| Route mapping | Found |
| RPKI Status | Unknown |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 12% | 2 | 2 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 12% | 2 | 2 |
| reputation | 8% | 1 | 2 |
| geolocation | 12% | 2 | 2 |
| Overall | 11% | 10 | 11 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-20 06:30:44 UTC |
| Last Seen | 2026-09-02 22:45:05 UTC |
| Profile Built | 2026-08-31 11:53:07 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 28 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 41.138.89.216
Who owns the IP address 41.138.89.216?
41.138.89.216 is registered to ETISALAT BENIN SA. The address falls within the 41.138.89.0/24 network block. Registration is held at AFRINIC.
Where is 41.138.89.216 located?
Geolocation data places 41.138.89.216 in London, Littoral, United Kingdom. The local time zone is Europe/London. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 41.138.89.216 malicious or safe?
41.138.89.216 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.