# IP Intelligence Briefing: 41.231.226.114/32
Classification: Low Risk | Date: 2026-07-24
---
## Executive Summary
IP address 41.231.226.114/32 presents a low-risk profile with an overall risk score of 25. The address is attributed to ATI - Agence Tunisienne Internet (ASN 328880) under the ORG-ATIA2-AFRINIC network block. No active threat indicators were identified across all intelligence sources.
---
## Ownership and Network Classification
The IP belongs to ORG-ATIA2-AFRINIC, a Tunisian ISP organization registered under AFRINIC RIR. The CIDR block 41.224.0.0/13 encompasses the address. BGP analysis indicates the address originates from prefix 41.231.224.0/22. Route stability was assessed as unstable with route changes observed within the 30-day period. RPKI validation status could not be determined.
---
## Geolocation Discrepancy
Geolocation data presents conflicting information. The primary profile indicates United States (Boston, MA), while historical signal observations consistently report Tunisia (Tunis). This geo-validation failure suggests potential routing anomalies or inconsistent geolocation databases. The minimum possible RTT was not measurable.
---
## Threat Assessment
Threat indicators remained absent across all evaluated sources. The IP was not identified as a known attacker, spam source, or Tor exit node. Abuse confidence score was not available. Blacklist enumeration returned zero listings in the primary check, though DNSBL analysis revealed one listing out of eight total checked lists. No known campaigns were associated with this address.
---
## Network Behavior and Services
No open ports were detected; the IP classification indicates "Firewalled / No Services." DNS analysis showed no PTR records and zero forward resolution count. Email authentication (SPF, DMARC) could not be verified. Behavioral analysis recorded zero honeypot hits, zero enumeration strikes, and zero WAF violations.
---
## Neighborhood Analysis
The /24 subnet (41.231.226.114/24) was classified as clean with an abuse density of 0. No sibling IPs were identified as active or threatening. Risk inheritance from the subnet was zero.
---
## Historical Signals
Twelve observations were recorded. Geolocation signals consistently reported Tunisia (TN). Ownership stability showed zero changes. The operator score maintained at 0.1304 with a label of "Minimal." No threat persistence was observed.
---
## Recommended Actions
No specific security actions or firewall rules were generated based on the low-risk profile. The IP does not require immediate blocking or mitigation measures. Standard monitoring practices are recommended.
---
Analyst Notes: While the IP presents low threat indicators, the geolocation discrepancy between US and Tunisia warrants attention. The conflicting location data may indicate routing anomalies or misconfigured geolocation databases. Continue monitoring for any changes in behavior or classification.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | ATI - Agence Tunisienne Internet |
| ASN | AS328880 |
| Network Name | ORG-ATIA2-AFRINIC |
| CIDR Block | 41.224.0.0/13 |
| RIR | AFRINIC |
| Country | TN |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS328880 |
| Network Prefix | 41.231.224.0/22 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-07 18:43:44 UTC |
| Last Seen | 2026-08-27 05:45:03 UTC |
| Profile Built | 2026-08-29 05:41:25 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 17 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 41.231.226.114
Who owns the IP address 41.231.226.114?
41.231.226.114 is registered to ATI - Agence Tunisienne Internet. The address falls within the 41.224.0.0/13 network block. Registration is held at AFRINIC.
Where is 41.231.226.114 located?
Geolocation data places 41.231.226.114 in Boston, US-MA, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 41.231.226.114 malicious or safe?
41.231.226.114 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.