IPDebrief

41.219.71.253

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# INTELLIGENCE BRIEFING: 41.219.71.253

Classification: Moderate Risk (Score: 50/100)

Report Generated: 2026-07-30

Analyst: IPDebrief SOC Intelligence

---

## EXECUTIVE SUMMARY

IP 41.219.71.253 presents a moderate risk profile with a stability score of 50. The address is classified as "Firewalled / No Services" with no open ports detected. While not flagged as a known attacker or spam source, the IP shows moderate risk indicators and is recommended for firewall filtering.

---

## OWNERSHIP & GEOLOCATION

AttributeValue
ASN37009
OrganizationWilson Andreas
Netname41.219.64.0 - 41.219.95.255
CIDR Block41.219.64.0/19
RIRAFRINIC
CountryFrance (FR)
CityMarseille
TimezoneEurope/Paris
GeoValidationPlausible (Consensus: true)

---

## THREAT INDICATORS

---

## NETWORK CLASSIFICATION

---

## CONTROL PLANE ANALYSIS

---

## NEIGHBORHOOD ANALYSIS

MetricValue
Subnet41.219.71.253/24
Abuse Density0
ClassificationClean
Total Siblings2
Active Siblings0
Threat Siblings0
Neighbor IPs41.219.71.157 (Risk: 40)

The /24 neighborhood shows low abuse density with one neighboring IP (41.219.71.157) scoring 40 risk.

---

## OBSERVATION HISTORY

Total Observations: 12

Recent signals indicate:

---

## RELATIONSHIP GRAPH

Five relationships identified, all pointing to the same network block (41.219.64.0 - 41.219.95.255), confirming consistent network attribution.

---

## RECOMMENDED ACTIONS

Based on the moderate risk profile, the following firewall rules are recommended:

PlatformRule
iptables`iptables -A INPUT -s 41.219.71.253 -j DROP`
nftables`nft add rule inet filter input ip saddr 41.219.71.253 drop`
nginx`deny 41.219.71.253;`
pfSense`41.219.71.253/32`
Cloudflare WAFBlock IP (risk score: 50)
AWS WAFAdd IP to block list

---

## SOC ANALYST NOTES

1. Risk Level: Moderate (50/100) โ€” warrants monitoring but not immediate blocking

2. Primary Concern: No services detected, IP appears firewalled; low activity level

3. Network Context: Part of larger /19 block (41.219.64.0/19) with minimal operator score

4. Action: Recommended for firewall filtering based on risk profile; verify against local threat intelligence before permanent block

---

END OF BRIEFING

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ซ๐Ÿ‡ท France
Region93
CityMarseille
TimezoneEurope/Paris
Latitude43.30
Longitude5.38

๐Ÿข Ownership & Registration

OrganizationWilson Andreas
ASNAS37009
Network Name41.219.64.0 - 41.219.95.255
CIDR Block41.219.64.0/19
RIRAFRINIC
CountryNA
Abuse Contactโ€”

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFPresent
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
ServerApache
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_7.4

๐Ÿ” TLS Certificate

An expired certificate for CN=missnamibia.org was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.
๐Ÿ”’
CN=missnamibia.org
Issued by CN=R12, O=Let's Encrypt, C=US
Self-signed: No
SANsmissnamibia.org
Valid From2026-05-07T06:27:27+00:00
Valid Until2026-08-05T06:27:26+00:00 (expired)
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period89 days
Serial Number06FC6F4E222106463935BF88A57444D3631E
ThumbprintEE7BCA6354541FBAF001FB2BA129AF72439443B0

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
28%
22
routing
20%
11
services
40%
23
ownership
28%
22
reputation
20%
12
geolocation
0%
00
Overall22%810
Coverage: 5/6 dimensions ยท Data sufficiency: partial
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Geo sources disagree on country: NA, FR

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-24 20:34:18 UTC
Last Seen2026-08-13 06:44:53 UTC
Profile Built2026-08-10 05:13:23 UTC
Data FreshnessLive
Signal Types17
Total Observations18
๐Ÿ” 17 signal types ยท 18 observations collected
This report is generated from 17+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.