## INTELLIGENCE BRIEFING: IP 41.214.55.235/32
Classification: HIGH RISK
Date of Analysis: 2026-07-29
Report Type: Network Threat Intelligence
---
Executive Summary
IP 41.214.55.235 presents a HIGH RISK threat profile with a composite risk score of 80/100. The address is listed on four DNS blacklists with maximum severity classifications. While no active services are exposed, the IP demonstrates persistent threat indicators and geographic data inconsistencies warranting further investigation.
---
Threat Profile
Risk Assessment:
- Overall Risk Score: 80/100 (HIGH)
- Abuse Confidence: Listed on 4 of 8 DNS blacklists
- Control Plane Risk: DNSBL listings across 8 total threat feeds
Network Classification:
- Service Status: Firewalled / No Services Detected
- Open Ports: None identified
- TLS/HTTP: No certificates, no HTTP title, no banner responses
- Network Role: Not classified as provider, CDN, VPN, proxy, or hosting infrastructure
---
Geolocation & Routing Discrepancy
Observed Conflict:
- Profile Geolocation: United Kingdom (GB) - London
- ASN Data (8346): Senegal (SN) - SONATEL - IDDQD-AS
- BGP Prefix: 41.214.0.0/17
- Geographic Validation: geoPlausible flag set to FALSE
This geographic inconsistency between observed location and autonomous system registry data indicates potential routing anomalies or misconfigured infrastructure.
---
Historical Observation Timeline
Total Observations: 8 signals recorded
- Most Recent (2026-07-29 15:22:29): DNSSEC validation confirmed, low confidence (0.30)
- Blacklist Activity (2026-07-29 10:35:13): 4 of 8 DNSBL listings with HIGH severity rating
- ASN Confirmation (2026-07-29 10:35:11): ASN 8346, prefix 41.214.0.0/17, registry Afrinic, allocated 2009-01-23
- DNSSEC Status: Valid RRSIG confirmed
---
Relationship & Neighborhood Analysis
Direct Relationships: None identified (0 correlated entities)
Subnet Analysis: 41.214.55.235/24
- Neighbor Count: 0
- Abuse Density: 0
- Threat Siblings: None observed
Control Plane:
- Origin ASN: 8346
- BGP Prefix: 41.214.0.0/17
- Route Stability: Unstable (false)
- RPKI/Irr: Inconsistent status
---
Behavioral Indicators
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: 0
- Auto-Banned: No
- Active Attacker Status: False
Network Traceroute:
- Hop Count: 20
- First Hop RTT: 0.2ms
- Last Hop RTT: 154.5ms
- Timed Out Hops: 2
- Transit Networks: Comcast, Cogent
---
Recommended Actions
1. BLOCK at perimeter firewall (iptables/nftables) - High risk score with blacklist presence
2. Monitor for service emergence - Currently firewalled but risk profile suggests potential for exploitation
3. Investigate geographic discrepancy between GB profile data and SN ASN registration
4. Correlate with other IPs in 41.214.0.0/17 prefix for campaign indicators
5. Review DNSBL listings for specific blacklist sources and removal procedures
---
Confidence Assessment
- Overall Confidence: Low to Moderate
- Data Sufficiency: Limited by lack of direct relationships and neighborhood data
- Temporal Persistence: Threat observation count at 0; requires extended monitoring
Status: REQUIRES MONITORING - High risk classification with insufficient behavioral data for definitive attribution.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Alpha Mbodj |
| ASN | AS8346 |
| Network Name | 41.214.55.0 - 41.214.55.255 |
| CIDR Block | 41.214.55.0/24 |
| RIR | AFRINIC |
| Country | SN |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 23% | 1 | 1 |
| routing | 23% | 1 | 1 |
| services | 23% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 11% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 19:33:08 UTC |
| Last Seen | 2026-08-13 06:44:53 UTC |
| Profile Built | 2026-08-07 07:34:45 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 15 |
Full dossier details are available via our API.