IP Intelligence Briefing: 41.216.215.145
*Generated via IPDebrief analysis tools*
---
**Key Findings**
1. Risk Profile:
- Overall Risk: High (70/100)
- Ownership: Registered to Tarisai Masenda (AFRINIC) with CIDR 41.216.214.0/23.
- Geolocation: Botswana (BW), flagged as plausibly geographically inconsistent (geoPlausible: false).
- Network Role: Single-service host running lighttpd/1.4.39 on port 80 (HTTP).
2. Threat Indicators:
- No direct malware, phishing, or exploit indicators detected.
- DNSBL Listings: Identified in 4/8 DNSBLs (low-severity).
- BGP Analysis: Subnet 41.216.208.0/21 shows route instability (isRouteStable: false).
3. Neighbor Subnet (41.216.215.145/24):
- Abuse Density: 16.7% (mixed risk).
- High-Risk Neighbors: 1 IP (80/100), 4 medium-risk (70/100), 1 low-risk (0/100).
- Active Siblings: 2 IPs; 3 flagged as potentially malicious.
4. Observation History (Last 30 Days):
- Scans: Detected as a single-service host with HTTP service (302 redirect).
- Stability: No persistent malicious activity (threatPersistenceDays: 0).
- DNS: No DNS resolution or email authentication records.
---
**Actionable Insights**
- Monitor Neighbors: The subnet contains 3 IPs with elevated risk scores. Investigate potential lateral movement or shared infrastructure.
- Server Hardening: The outdated lighttpd/1.4.39 server may have unpatched vulnerabilities. Update to a supported version.
- DNSBL Investigation: Despite no direct threats, the DNSBL listings suggest potential spam or abuse activity. Verify with upstream providers.
- Geolocation Anomaly: Botswanaβs IP geolocation may be misconfigured or spoofed. Validate with additional geolocation sources.
---
**Recommended Actions**
1. Block High-Risk Neighbors: Apply firewall rules to isolate or block IPs with >70 risk scores in the 41.216.215.0/24 subnet.
2. Scan for Vulnerabilities: Perform a vulnerability scan on the HTTP service (port 80) to confirm the lighttpd version and check for exploits.
3. Monitor BGP Activity: Track BGP prefix 41.216.208.0/21 for route changes or hijacking attempts.
4. Verify DNS Configuration: Ensure DNS records for this IP are not being used for malicious redirection or phishing.
---
*End of briefing. Generated from IPDebrief intelligence tools.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Tarisai Masenda |
| ASN | AS37678 |
| Network Name | 41.216.214.0 - 41.216.215.255 |
| CIDR Block | 41.216.214.0/23 |
| RIR | AFRINIC |
| Country | BW |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| Closed Ports | 22, 25, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | lighttpd/1.4.39 |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 19% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 27% | 2 | 3 |
| ownership | 19% | 2 | 2 |
| reputation | 13% | 1 | 2 |
| geolocation | 13% | 1 | 1 |
| Overall | 17% | 9 | 11 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-14 19:29:17 UTC |
| Last Seen | 2026-06-25 14:02:32 UTC |
| Profile Built | 2026-06-23 20:19:38 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.