IPDebrief

41.56.174.147

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING: 41.56.174.147

Date: 2026-07-23

Analyst: IPDebrief SOC

Classification: Routine Monitoring

---

## EXECUTIVE SUMMARY

IP address 41.56.174.147 is classified as LOW RISK with a risk score of 25/100. The address shows minimal malicious activity indicators, no known threat associations, and no active services. However, geolocation inconsistencies and limited DNSBL presence warrant continued monitoring.

---

## NETWORK OWNERSHIP & CLASSIFICATION

AttributeValue
**ASN**37105
**Organization**rain admin role
**Netname**ORG-RGHL1-AFRINIC
**CIDR Block**41.56.128.0/18
**RIR**AFRINIC
**Network Role**Firewalled / No Services
**Infrastructure Type**Not Classified

Key Finding: The IP is assigned to an AFRINIC-regulated network with no identified hosting or CDN services. The address is currently firewalled with no open ports or active services detected.

---

## GEOLOCATION ANALYSIS

AttributeValue
**Primary Location**Miami, FL, US
**Secondary Location**Bryanston, Johannesburg, ZA
**GeoConsensus****FALSE**
**GeoPlausible****FALSE**
**Source Count**2

Key Finding: Significant geolocation inconsistency detected. The IP shows conflicting location data between US and South Africa. This inconsistency reduces confidence in geolocation accuracy and may indicate routing anomalies or spoofing.

---

## THREAT INTELLIGENCE

IndicatorStatus
**Risk Score**25 (Low Risk)
**Blacklist Count**0
**DNSBL Listed**1 of 8 lists
**Known Attacker**No
**Spam Source**No
**Tor Exit Node**No
**Active Threats**None Detected
**Known Campaigns**None

Key Finding: No active threat indicators present. The IP has minimal DNSBL presence (1 listing out of 8 evaluated) but no confirmed malicious reputation.

---

## OBSERVATION HISTORY

Total Observations: 10

Recent Activity Timeline:

Temporal Analysis:

Key Finding: Historical data shows stable network ownership with no significant threat escalation. One high-severity DNSBL listing was observed, but no sustained malicious activity pattern.

---

## NETWORK RELATIONSHIPS

Relationship TypeTarget
Same NetworkORG-RGHL1-AFRINIC

Key Finding: Limited relationship graph with only one organizational network association. No related hostnames, certificates, or external IP associations detected.

---

## NEIGHBORHOOD ANALYSIS

AttributeValue
**Subnet**41.56.174.147/24
**Neighbor Count**0
**Abuse Density**0
**High Risk Neighbors**0
**Threat Siblings**0

Key Finding: The /24 subnet shows zero neighbor activity and minimal abuse density. No adjacent IP addresses are classified as threats.

---

## ROUTING & CONTROL PLANE

MetricValue
**Hop Count**30
**Timed Out Hops**21
**Transit Networks**Comcast, Lumen
**Route Stability**False
**RPKI State**Not Evaluated
**IRR Consistency**Not Evaluated

Key Finding: Routing path shows 30 hops with 21 timeouts, indicating potential network instability or complex routing topology. Route stability is flagged as false.

---

## NETWORK SERVICES

Service TypeStatus
**Open Ports**None
**TLS Certificate**Not Detected
**HTTP Title**Not Detected
**Server Banner**Not Detected
**Certificates**None

Key Finding: No services detected on the IP. This is consistent with a firewalled or non-public IP address.

---

## ACTIONS & RECOMMENDATIONS

Recommended Actions

Firewall Rules

No specific firewall rules required based on current risk assessment. Standard monitoring protocols apply.

---

## CONCLUSION

IP 41.56.174.147 presents a LOW RISK profile with no active threat indicators. The primary concerns are geolocation inconsistencies and routing instability, neither of which indicate active malicious activity at this time. The IP shows no evidence of being used as a spam source, attacker, or proxy.

Suggested Priority: Standard monitoring

Threat Level: Low

Recommended Action: Continue standard intelligence gathering; no immediate defensive action required.

---

*Intelligence produced by IPDebrief SOC Analysis Platform*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇿🇦 South Africa
RegionWestern Cape
CityCape Town
TimezoneAfrica/Johannesburg
Latitude-33.91
Longitude18.41

🏢 Ownership & Registration

Organizationrain admin role
ASNAS37105
Network NameORG-RGHL1-AFRINIC
CIDR Block41.56.128.0/18
RIRAFRINIC
CountryZA
Abuse Contact—

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)

🔐 DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS37105
Network Prefix41.56.128.0/18
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
25%
11
Overall16%44
Coverage: 4/6 dimensions · Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-05 11:43:16 UTC
Last Seen2026-08-27 07:26:57 UTC
Profile Built2026-08-29 05:18:15 UTC
Data FreshnessLive
Signal Types15
Total Observations16
🔍 15 signal types · 16 observations collected
This report is generated from 15+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 41.56.174.147

Who owns the IP address 41.56.174.147?

41.56.174.147 is registered to rain admin role. The address falls within the 41.56.128.0/18 network block. Registration is held at AFRINIC.

Where is 41.56.174.147 located?

Geolocation data places 41.56.174.147 in Cape Town, Western Cape, South Africa. The local time zone is Africa/Johannesburg. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 41.56.174.147 malicious or safe?

41.56.174.147 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.