# IP Intelligence Briefing: 41.59.36.228/32
Classification: Moderate Risk – Defensible Traffic Pattern
Report Date: 2026-07-28
Data Source: IPDebrief Intelligence Platform
---
## Executive Summary
IP address 41.59.36.228 is classified as Moderate Risk (Score: 40/100) with no active threat indicators. The IP shows no evidence of malicious activity, no known campaign associations, and operates within a clean network neighborhood. Geographic metadata indicates a potential inconsistency requiring validation.
---
## Ownership & Registration
| Attribute | Value |
|---|---|
| **ASN** | 33765 |
| **Organization** | Adam L Mwaipungu |
| **Network Block** | 41.59.0.0/17 (41.59.0.0 - 41.59.127.255) |
| **RIR** | AFRINIC (Tanzania) |
| **Classification** | Not Provider/Infrastructure |
---
## Geolocation Discrepancy
Critical Finding: Geographic metadata shows conflicting data requiring analyst validation.
| Signal | Value |
|---|---|
| **Reported Country** | France (FR) – Marseille |
| **Registration RIR** | AFRINIC (Tanzania/TZ) |
| **Distance from Claimed Location** | 7,279.2 km |
| **Minimum Possible RTT** | 145.6 ms |
| **Observed RTT (Avg)** | 291.4 ms |
| **Geo Plausibility** | Validated |
The ~7,000 km distance and 287-296ms observed RTT from Marseille, combined with AFRINIC registration, suggests either legitimate routing anomalies or potential spoofing. Investigation recommended if traffic patterns warrant scrutiny.
---
## Threat Assessment
Current Status: Clean / No Active Threats
- Blacklist Count: 0
- DNSBL Listed: 2 of 8 total lists
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Honeypot Hits: 0
- WAF Violations: 0
- Is Persistently Malicious: No
---
## Network State
- Open Ports: None detected
- HTTP Services: None (Firewalled / No Services)
- TLS Certificates: None
- Forward Resolution: 0 hostnames
- PTR Records: None
---
## Neighborhood Analysis (41.59.36.0/24)
- Abuse Density: 0 (Clean)
- Threat Siblings: 0
- Active Siblings: 0
- Total Subnet IPs: 1
The /24 subnet shows no associated abuse activity. No sibling IPs flagged as threats.
---
## Historical Observations
Total Signals: 15 observations
- Ownership Changes: 0 (Stable)
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Recent Activity: Server banner detection (GoAhead-Webs) on 2026-07-28
The IP has demonstrated stable ownership with no escalation in threat signals over the observation period.
---
## Recommended Actions
Risk Score: 40 – Moderate
Recommended Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 41.59.36.228 -j DROP
# nftables
nft add rule inet filter input ip saddr 41.59.36.228 drop
# Cloudflare WAF
Block 41.59.36.228 — IPDebrief risk score 40
# AWS WAF
Addresses: 41.59.36.228/32
Description: IPDebrief risk 40
```
Note: These recommendations are probabilistic. Verify against organizational threat context before implementation.
---
## SOC Analyst Guidance
1. Monitor for Service Changes: The IP is currently firewalled with no open ports. Monitor for service emergence.
2. Validate Geographic Claims: The France/Tanzania discrepancy warrants context-specific investigation if traffic originates from this IP.
3. DNSBL Monitoring: Two DNSBL listings detected. Monitor for additional blacklist additions.
4. Subnet Context: The /24 subnet remains clean—no lateral threat indicators present.
5. Risk Threshold: Score of 40 falls below typical block thresholds (typically 60+). Recommend observation unless additional contextual threats emerge.
---
End of Briefing
*Generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Adam L Mwaipungu |
| ASN | AS33765 |
| Network Name | 41.59.0.0 - 41.59.127.255 |
| CIDR Block | 41.59.0.0/17 |
| RIR | AFRINIC |
| Country | TZ |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS33765 |
| Network Prefix | 41.59.36.0/24 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 17% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 23% | 2 | 4 |
| ownership | 12% | 2 | 2 |
| reputation | 8% | 1 | 2 |
| geolocation | 25% | 2 | 3 |
| Overall | 15% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-17 23:22:24 UTC |
| Last Seen | 2026-09-20 19:35:54 UTC |
| Profile Built | 2026-09-22 17:09:46 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 41.59.36.228
Who owns the IP address 41.59.36.228?
41.59.36.228 is registered to Adam L Mwaipungu. The address falls within the 41.59.0.0/17 network block. Registration is held at AFRINIC.
Where is 41.59.36.228 located?
Geolocation data places 41.59.36.228 in Marseille, Dar es Salaam Region, France. The local time zone is Europe/Paris. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 41.59.36.228 malicious or safe?
41.59.36.228 currently carries a high risk assessment, meaning indicators associated with malicious or abusive activity have been observed. This assessment is generated from continuously collected signals and can change over time.