# IP Intelligence Briefing: 41.33.1.91/32
Classification: Moderate Risk | Data Source: IPDebrief | Date: 2026-07-23
## Executive Summary
IP 41.33.1.91 is a moderately risky Egyptian origin address (Risk Score: 40) assigned to TE Data Contact Role under ASN 8452. The address is located in Cairo Governorate and shows no active services, open ports, or known malicious indicators. However, it is listed on 2 of 8 DNSBLs and requires monitoring.
## Technical Profile
Ownership & Network
- ASN: 8452
- Organization: TE Data Contact Role
- CIDR Block: 41.33.0.0/16
- RIR: AFRI Nic
- Network Classification: Firewalled / No Services
Geolocation
- Country: Egypt (EG)
- Region: Cairo Governorate
- City: Cairo
- Coordinates: 26.82°N, 30.8°E (600km accuracy radius)
- Geo Confidence: 0.52 (Multi-signal inference)
Threat Indicators
- Risk Score: 40 (Moderate)
- Abuse Confidence Score: Not reported
- Blacklist Count: 0 (traditional lists)
- DNSBL Status: Listed on 2 of 8 total DNSBLs
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
## Network Behavior & Services
Service Status: No services detected (Firewalled)
- Open Ports: None
- DNS Resolution: No PTR records; forward resolution failed
- HTTP/HTTPS: No TLS certificate; no HTTP title; no server banner
- Cloud/CDN/VPN/Proxy: Negative indicators across all categories
Routing Analysis
- BGP Prefix: 41.33.0.0/17
- Route Stability: False (changing)
- RPKI State: Not validated
- IRR Consistency: Not reported
- Hop Count: 30 (22 timed out)
- First Hop RTT: 0.2ms | Last Hop RTT:** 156.2ms
## Neighborhood Analysis (41.33.1.0/24)
The /24 subnet contains 3 sibling IPs with the following risk distribution:
- 41.33.1.89: Risk Score 40 (Medium) | Authority Score 50
- 41.33.1.90: Risk Score 0 (Low) | Authority Score 50
- 41.33.1.94: Risk Score 55 (High) | Authority Score 50
Subnet abuse density: 0. The presence of 41.33.1.94 (Risk Score 55) suggests potential neighborhood-level risk activity that may correlate with 41.33.1.91.
## Relationship Graph
- Same Network Relationships: 41.33.0.0 - 41.33.255.255 (2 entries)
- External Relationships: None detected
- Campaign Correlations: 0 correlated IPs; 0 certificate matches
## Historical Observations
Total Signals: 14 observations
- Recent Activity: 2026-07-23T19:26:21 - 2026-07-23T19:28:03
- Ownership Changes: 0
- Threat Persistence Days: 0
- Persistently Malicious: False
Geolocation signals remain consistent (Egypt) with no observed degradation or escalation in threat indicators.
## Recommended Actions
Based on risk score 40 and DNSBL presence, implement the following controls:
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 41.33.1.91 -j DROP
# nftables
nft add rule inet filter input ip saddr 41.33.1.91 drop
# nginx
deny 41.33.1.91;
```
Cloud Platform Rules:
- Cloudflare WAF: Block with filter expression `ip.src eq 41.33.1.91`
- AWS WAF: Add address `41.33.1.91/32` with description "IPDebrief risk 40"
## Intelligence Assessment
IP 41.33.1.91 presents moderate risk due to:
1. DNSBL listing on 2 of 8 lists
2. Neighborhood presence of higher-risk sibling (41.33.1.94 with Risk Score 55)
3. Route instability (changing BGP prefix)
However, the IP shows no active services, no known threat indicators, and no evidence of persistent malicious activity. SOC teams should monitor for behavioral changes, particularly if 41.33.1.94 initiates correlation activity.
Threat Level: Moderate | Action Required: Monitor and block outbound connections if policy permits
---
*Report generated by IPDebrief Intelligence Platform. All data sourced from real-time network observations.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | TE Data Contact Role |
| ASN | AS8452 |
| Network Name | 41.33.0.0 - 41.33.255.255 |
| CIDR Block | 41.33.0.0/16 |
| RIR | AFRINIC |
| Country | EG |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS8452 |
| Network Prefix | 41.33.0.0/17 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 22% | 6 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-05 11:43:16 UTC |
| Last Seen | 2026-08-27 02:02:48 UTC |
| Profile Built | 2026-08-29 06:32:49 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 17 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 41.33.1.91
Who owns the IP address 41.33.1.91?
41.33.1.91 is registered to TE Data Contact Role. The address falls within the 41.33.0.0/16 network block. Registration is held at AFRINIC.
Where is 41.33.1.91 located?
Geolocation data places 41.33.1.91 in Cairo, Cairo Governorate, Egypt. The local time zone is Africa/Cairo. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 41.33.1.91 malicious or safe?
41.33.1.91 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.