IP INTELLIGENCE BRIEFING: 41.237.22.147/32
Classification: LOW RISK โ Legitimate Infrastructure
Date: Current Assessment
Analyst: SOC Intelligence
---
**EXECUTIVE SUMMARY**
IP 41.237.22.147 is a low-risk Egyptian infrastructure address belonging to TE Data Contact Role (ASN 8452). The IP demonstrates no active threat indicators, no open services, and no historical malicious behavior. The subnet exhibits clean classification with zero abuse density.
---
**RISK PROFILE**
| Metric | Value |
|---|---|
| **Overall Risk Score** | 25 / 100 (Low) |
| **Reputation** | Low Risk |
| **Blacklist Count** | 0 |
| **Abuse Confidence** | Not applicable |
| **Is Tor/Exit** | No |
| **Is Known Attacker** | No |
| **Is Spam Source** | No |
Network Classification: Firewalled / No Services
Operator Label: Minimal (0.1304)
---
**OWNERSHIP & GEOGRAPHY**
- Organization: TE Data Contact Role
- Netname: ORG-TD2-AFRINIC
- ASN: 8452
- RIR: AFRINIC
- Country: Egypt (EG)
- Region: Alexandria
- BGP Prefix: 41.237.0.0/18
- CIDR Block: 41.237.0.0/16
Traceroute: 30 hops via Comcast and Cogent transit networks.
---
**THREAT INDICATORS**
- Active Indicators: None
- Threat Feeds: Empty
- Known Campaigns: None
- Campaign Likelihood: Not applicable
- DNSBL Listed: 1 of 8 lists (minor listing)
Persistence Analysis:
- Threat Observation Count: 0
- Threat Persistence Days: 0
- Persistently Malicious: No
- Ownership Changes: 0
---
**NETWORK SERVICES**
| Service Type | Status |
|---|---|
| Open Ports | None detected |
| TLS Certificate | None |
| HTTP Title | None |
| Hosted Domains | 0 |
| Email Auth (SPF/DMARC) | Not configured |
Forward Resolution: No PTR records or forward DNS resolution
---
**NEIGHBORHOOD ANALYSIS (41.237.22.0/24)**
- Subnet Classification: Clean
- Abuse Density: 0
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 0
- Risk Distribution: High: 0, Medium: 0, Low: 0
Conclusion: No correlated threats in the /24 subnet.
---
**RELATIONSHIP GRAPH**
All 5 detected relationships link to ORG-TD2-AFRINIC (same network). No external entity associations (hostnames, certificates, or organizations) detected.
---
**HISTORICAL OBSERVATIONS (13 Total Signals)**
Recent activity (July 30, 2026) confirms:
- Geo-inference: Egypt (26.82°N, 30.8°E) โ Confidence: 52%
- Traceroute: Reached target via 30 hops โ Confidence: 75%
- Ownership signals: No changes โ Confidence: 85%
- Operator score: Minimal (0.1304) โ Confidence: 30%
Temporal Analysis: No evidence of escalating risk or behavioral change.
---
**RECOMMENDED ACTIONS**
| Action | Priority | Rationale |
|---|---|---|
| **Block/Allow:** Review firewall rules | Low | IP shows no active threat behavior |
| **Monitor:** Standard traffic monitoring | Low | Routine observation sufficient |
| **Investigate:** None required | N/A | No threat indicators present |
Firewall Recommendation: No specific deny rules warranted. Treat as legitimate infrastructure traffic from Egypt.
---
**ASSESSMENT CONCLUSION**
IP 41.237.22.147 represents standard, low-risk infrastructure from TE Data in Alexandria, Egypt. The address exhibits no malicious indicators, maintains clean neighborhood classification, and shows no historical threat activity. SOC teams may treat this IP as benign unless correlated with other contextual threat intelligence.
Status: Clear for standard operations.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | TE Data Contact Role |
| ASN | AS8452 |
| Network Name | ORG-TD2-AFRINIC |
| CIDR Block | 41.237.0.0/16 |
| RIR | AFRINIC |
| Country | EG |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 1 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 22% | 6 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-24 20:34:18 UTC |
| Last Seen | 2026-07-30 01:19:25 UTC |
| Profile Built | 2026-07-30 01:35:02 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.