# IP Intelligence Briefing: 41.173.37.99/32
Classification: Moderate Risk
Report Date: 2026-07-31
## Executive Summary
IP 41.173.37.99 is assigned to organization ORG-LTOL1-AFRINIC (Rob Davelaar) under ASN 37332. The address exhibits moderate risk characteristics (score: 50) with no active threat indicators. Geolocation data indicates Zimbabwe (ZW) with coordinates -19° latitude, 29.75° longitude. The subnet 41.173.37.0/24 shows mostly_clean classification with low inherited risk (2) and minimal abuse density (1).
## Network Profile
| Attribute | Value |
|---|---|
| **ASN** | 37332 |
| **Organization** | Rob Davelaar |
| **Netname** | ORG-LTOL1-AFRINIC |
| **RIR** | AFIRNIC |
| **CIDR Block** | 41.160.0.0/12 |
| **Country** | Zimbabwe (ZW) |
| **Risk Score** | 50 (Moderate) |
| **Status** | Firewalled / No Services |
## Threat Indicators
- Blacklist Count: 0
- DNSBL Lists: 2 of 8 total lists
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Campaign Matches: 0
- Honeypot Hits: 0
- WAF Violations: 0
## Control Plane Analysis
- BGP Prefix: 41.173.37.0/24
- Route Stability: False (isRouteStable)
- Operator Score: 0.1304 (Minimal)
- RPKI State: Not evaluated
- DNSSEC: Valid
## Neighborhood Assessment
The /24 subnet (41.173.37.0/24) contains:
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 1
- Abuse Density: 1 (Low)
- Classification: mostly_clean
No adjacent IPs show significant threat activity.
## Observation History
11 observations recorded as of 2026-07-31. Key signals include:
- Geolocation consistently reported as Zimbabwe (ZW)
- ASN registration under Afrinic RIR
- Operator score observed at 0.1304 (Minimal)
- Subnet abuse density maintained at 1
- Some observations show low confidence (0.21-0.30)
No persistent malicious behavior detected over the observation period.
## Relationship Graph
Single relationship identified:
- Type: Same Network
- Target: ORG-LTOL1-AFRINIC
No external relationships to hostnames, certificates, or related organizations detected.
## Security Recommendations
Based on the moderate risk classification with no active threats:
1. Monitor - Continue standard monitoring of this IP. The moderate risk score warrants baseline surveillance.
2. No Immediate Blocking - The IP does not show active threat indicators. Blocking may impact legitimate traffic.
3. Validate Geolocation - Geographic inconsistencies observed (ZW vs MU in some signals) warrant validation.
4. Subnet Analysis - Consider broader analysis of 41.160.0.0/12 for potential related activity.
5. DNSBL Review - Two DNSBL listings detected; investigate potential sources.
## SOC Action Notes
- IP is currently firewalled with no open ports or active services
- No certificates or hosted domains associated
- No email authentication records (SPF/DMARC) detected
- No correlated IPs or campaign matches identified
Threat Level: LOW-MODERATE
Action Required: MONITOR
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Rob Davelaar |
| ASN | AS37332 |
| Network Name | ORG-LTOL1-AFRINIC |
| CIDR Block | 41.160.0.0/12 |
| RIR | AFRINIC |
| Country | MU |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 50% | 2 | 3 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 2 |
| geolocation | 0% | 0 | 0 |
| Overall | 20% | 5 | 7 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-30 17:12:10 UTC |
| Last Seen | 2026-08-05 06:12:25 UTC |
| Profile Built | 2026-07-31 04:09:55 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.