Threat Intelligence Briefing for IP 41.204.63.118/32
Summary
The IP address 41.204.63.118/32 is associated with Michael Komla Nfodzo (ASN 29614) and located in Accra, Ghana. While its base risk score is 65 (Moderate Risk), historical observations indicate it has been linked to botnet activity and exhibits mixed network behavior.
Key Findings
1. Ownership & Geolocation
- Owned by Michael Komla Nfodzo (Ghanaian entity).
- Geolocated to Accra, Greater Accra Region, Ghana (latitude 5.55, longitude -0.19).
- ASN 29614 registered with Afrinic (no abuse contact listed).
2. Network Behavior
- Services: HTTP (port 80), HTTPS (port 443), SSH (port 22), and HTTP-alt (port 8080).
- TLS Certificate: Valid Letβs Encrypt certificate for repository.ensign.edu.gh (subject SAN).
- Control Plane: BGP prefix 41.204.48.0/20, route stability flagged as unstable.
- DNSSEC: Validated, with CAA records present.
3. Threat Indicators
- Historical Signals:
- Observed in botnet activity (signal_type_id 6344, May 29, 2026).
- Multiple DNS and HTTP observations (22 total).
- Mixed risk scores (high-confidence threats detected in some signals).
- No Active Threats: Current threat indicators are empty, but historical data suggests past malicious activity.
4. Network Relationships
- Linked to 41.204.63.0/24 subnet (same network as profile).
- Subnet abuse density: 1/24 (low), but 1 threat sibling detected in neighbors.
5. Actionable Insights
- Monitor: Track DNS and HTTP activity for anomalies.
- Block: Consider blocking based on historical botnet associations.
- Verify: Confirm ownership legitimacy and investigate the repository.ensign.edu.gh domain.
Recommendations
- Add to intrusion detection rules for HTTP/HTTPS traffic.
- Monitor related subnets (41.204.63.0/24) for lateral movement.
- Validate SSL certificate validity and server configuration for vulnerabilities.
Note: The IPβs current risk profile is moderate, but historical data suggests it may have been compromised. Further investigation is advised.
---
*Generated from IPDebrief intelligence tools. Data as of 2026-06-06.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Michael Komla Nfodzo |
| ASN | AS29614 |
| Network Name | 41.204.63.0 - 41.204.63.255 |
| CIDR Block | 41.204.63.0/24 |
| RIR | AFRINIC |
| Country | GH |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| 8080 | http-alt | tcp | β |
| Closed Ports | 25, 3389, 8443 (4 open / 7 scanned) | ||
| Server | Apache/2.4.58 (Ubuntu) |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | repository.ensign.edu.gh |
| Valid From | 2026-05-11T09:12:24+00:00 |
| Valid Until | 2026-08-09T09:12:23+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 060D3C1AAA9CEFBF12B0E8303990B970562E |
| Thumbprint | 7A4EDACF7B6982265ECA2A37B380DF254C8CE529 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 25% | 1 | 1 |
| services | 23% | 2 | 4 |
| ownership | 15% | 2 | 2 |
| reputation | 16% | 1 | 3 |
| geolocation | 13% | 1 | 1 |
| Overall | 19% | 9 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-12 09:41:14 UTC |
| Last Seen | 2026-06-26 18:11:17 UTC |
| Profile Built | 2026-06-26 17:26:52 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 27 |
Full dossier details are available via our API.