# IP Intelligence Briefing: 41.210.170.238/32
Classification: Low Risk | Date: Current | Priority: Routine
## Executive Summary
IP address 41.210.170.238 presents a low-risk profile with no active threat indicators. The address is associated with MTN Uganda infrastructure but resolves to London, United Kingdom geolocation data. No malicious activity, blacklisting, or known campaign associations were detected across all monitoring periods.
## Risk Profile Assessment
- Overall Risk Score: 0 (Low Risk)
- Reputation: Low Risk
- Operator Score: 0.2609 (Basic classification)
- Abuse Density: 0%
- Blacklist Count: 0
- Threat Indicators: None detected
## Technical Profile
- Geolocation: London, United Kingdom (GB)
- ASN: 20294
- BGP Prefix: 41.210.160.0/20
- Network Role: Firewalled / No Services
- DNS Resolution: h2aee.n1.ips.mtn.co.ug
- PTR Record: h2aee.n1.ips.mtn.co.ug
- Forward Resolution: Confirmed
- DNSSEC Status: Valid
## Network Activity Analysis
- Open Ports: None detected
- TLS Certificates: None
- HTTP Services: None
- Honeypot Hits: 0
- WAF Violations: 0
- Enumeration Strikes: 0
- Total Incidents: 0
## Historical Signal Analysis
Observation history reveals 11 signals collected with no significant trend changes:
- DNSSEC validation confirmed in multiple observations
- Domain co.ug associated with no CAA records
- No persistent threat behavior observed
- Ownership and routing signals remain stable
- No evidence of escalation in risk profile
## Relationship Graph
The IP maintains minimal entity associations:
- DNS Associations: 2 (h2aee.n1.ips.mtn.co.ug)
- Organizational Links: None
- Certificate Associations: None
- Subnet Relationships: None detected
## Neighborhood Analysis
Subnet 41.210.170.238/24:
- Neighbor Count: 0
- Abuse Density: 0%
- Risk Distribution: No high, medium, or low risk neighbors detected
- Classification: None
## Geolocation Discrepancy Note
Geolocation data indicates London, UK, while DNS records associate with MTN Uganda (.co.ug domain). This geographic mismatch warrants monitoring but does not currently indicate malicious activity.
## Recommended Actions
- Monitoring: Continue passive observation
- Blocking: Not recommended (low risk, no threat indicators)
- Investigation: No immediate investigation required
- Policy: Treat as benign network traffic
## Conclusion
IP 41.210.170.238 demonstrates benign network characteristics with no evidence of malicious activity. The low-risk profile, absence of threat indicators, and stable historical signals support continued monitoring without intervention. The geolocation discrepancy between reported London location and Uganda DNS association should be noted for future reference but does not warrant immediate concern.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Munaawa Philip |
| ASN | AS20294 |
| Network Name | 41.210.160.0 - 41.210.175.255 |
| CIDR Block | 41.210.160.0/20 |
| RIR | AFRINIC |
| Country | UG |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | h2aee.n1.ips.mtn.co.ug |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | h2aee.n1.ips.mtn.co.ug |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 19:33:07 UTC |
| Last Seen | 2026-07-29 15:21:29 UTC |
| Profile Built | 2026-07-29 15:38:07 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.