# IP Intelligence Briefing: 41.139.28.217
## Executive Summary
IP address 41.139.28.217 was classified as Moderate Risk with a risk score of 55/100. The address is part of Teledata-AS (ASN 35091), registered to Gregory Eid in Ghana. While not currently flagged as a known attacker or spam source, the IP exhibits elevated risk characteristics with DNSBL listings and neighborhood abuse density.
## Ownership and Network Context
The IP address belongs to the 41.139.24.0 - 41.139.31.255 block, allocated to Teledata-AS (ASN 35091) under AFRINIC jurisdiction. Registration is attributed to Gregory Eid. Geolocation data places the address in Accra, Greater Accra Region, Ghana (5.55°N, -0.19°W). The network role is classified as a Web Server with HTTPS (port 443) open.
## Threat Indicators and Reputation
No known threat indicators were observed for this address. The IP is not identified as a Tor exit node, known attacker, or spam source. Blacklist counts returned zero. However, the control plane data indicates DNSBL listing on 3 of 8 total lists. The IP scored 0.1304 on the operator scale (labeled "Minimal") and exhibits route instability with isRouteStable=false.
## Behavioral and Service Analysis
The IP resolved to no PTR hostnames and exhibited no forward DNS resolution. No TLS certificates or HTTP titles were observed. Email authentication was not configured (no SPF, DMARC, or TXT records). The server fingerprint showed no HSTS, CSP, HTTP/2, or referrer policy headers.
## Neighborhood Analysis
The /24 subnet (41.139.28.0/24) contains 12 sibling IPs with 11 active. The subnet abuse density is 0.25 (25%), with 3 threat siblings identified. Risk distribution across neighbors: 1 high-risk, 10 medium-risk, 0 low-risk. Notable neighboring IPs include 41.139.28.178 (risk 80), 41.139.28.54 (risk 70), and 41.139.28.151 (risk 70).
## Historical Observations
Seventeen observations were recorded. ASN 35091 was confirmed on 2026-06-18 with a confidence score of 0.85. The subnet was classified as "mixed" with 25% abuse density and inherited risk of 7. Recent observations showed minimal operator scores and connection failures during HTTPS fingerprinting attempts.
## Recommended Actions
Based on the risk profile, the following actions are recommended:
Monitoring: Increase logging verbosity and review recent activity from this IP due to elevated risk score (55/100).
Firewall Rules:
- iptables: `iptables -A INPUT -s 41.139.28.217 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 41.139.28.217 drop`
- nginx: `deny 41.139.28.217;`
- pfSense: `41.139.28.217/32`
- Cloudflare WAF: Block with expression `ip.src eq 41.139.28.217`
- AWS WAF: Add address `41.139.28.217/32` to rule set
Note: These recommendations are probabilistic and should be combined with other signals before taking action.
## Conclusion
IP 41.139.28.217 presents moderate risk with no confirmed malicious activity but elevated neighborhood abuse density. The IP should be monitored closely, and blocking is recommended based on current risk scoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Gregory Eid |
| ASN | AS35091 |
| Network Name | 41.139.24.0 - 41.139.31.255 |
| CIDR Block | 41.139.24.0/21 |
| RIR | AFRINIC |
| Country | GH |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 18% | 2 | 2 |
| routing | 17% | 1 | 1 |
| services | 26% | 2 | 3 |
| ownership | 19% | 2 | 2 |
| reputation | 17% | 1 | 2 |
| geolocation | 21% | 2 | 2 |
| Overall | 20% | 10 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:19 UTC |
| Last Seen | 2026-06-23 12:12:52 UTC |
| Profile Built | 2026-06-23 12:31:13 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 23 |
Full dossier details are available via our API.