IPDebrief

41.59.36.228

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 41.59.36.228/32

Classification: Moderate Risk – Defensible Traffic Pattern

Report Date: 2026-07-28

Data Source: IPDebrief Intelligence Platform

---

## Executive Summary

IP address 41.59.36.228 is classified as Moderate Risk (Score: 40/100) with no active threat indicators. The IP shows no evidence of malicious activity, no known campaign associations, and operates within a clean network neighborhood. Geographic metadata indicates a potential inconsistency requiring validation.

---

## Ownership & Registration

AttributeValue
**ASN**33765
**Organization**Adam L Mwaipungu
**Network Block**41.59.0.0/17 (41.59.0.0 - 41.59.127.255)
**RIR**AFRINIC (Tanzania)
**Classification**Not Provider/Infrastructure

---

## Geolocation Discrepancy

Critical Finding: Geographic metadata shows conflicting data requiring analyst validation.

SignalValue
**Reported Country**France (FR) – Marseille
**Registration RIR**AFRINIC (Tanzania/TZ)
**Distance from Claimed Location**7,279.2 km
**Minimum Possible RTT**145.6 ms
**Observed RTT (Avg)**291.4 ms
**Geo Plausibility**Validated

The ~7,000 km distance and 287-296ms observed RTT from Marseille, combined with AFRINIC registration, suggests either legitimate routing anomalies or potential spoofing. Investigation recommended if traffic patterns warrant scrutiny.

---

## Threat Assessment

Current Status: Clean / No Active Threats

---

## Network State

---

## Neighborhood Analysis (41.59.36.0/24)

The /24 subnet shows no associated abuse activity. No sibling IPs flagged as threats.

---

## Historical Observations

Total Signals: 15 observations

The IP has demonstrated stable ownership with no escalation in threat signals over the observation period.

---

## Recommended Actions

Risk Score: 40 – Moderate

Recommended Firewall Rules:

```bash

# iptables

iptables -A INPUT -s 41.59.36.228 -j DROP

# nftables

nft add rule inet filter input ip saddr 41.59.36.228 drop

# Cloudflare WAF

Block 41.59.36.228 — IPDebrief risk score 40

# AWS WAF

Addresses: 41.59.36.228/32

Description: IPDebrief risk 40

```

Note: These recommendations are probabilistic. Verify against organizational threat context before implementation.

---

## SOC Analyst Guidance

1. Monitor for Service Changes: The IP is currently firewalled with no open ports. Monitor for service emergence.

2. Validate Geographic Claims: The France/Tanzania discrepancy warrants context-specific investigation if traffic originates from this IP.

3. DNSBL Monitoring: Two DNSBL listings detected. Monitor for additional blacklist additions.

4. Subnet Context: The /24 subnet remains clean—no lateral threat indicators present.

5. Risk Threshold: Score of 40 falls below typical block thresholds (typically 60+). Recommend observation unless additional contextual threats emerge.

---

End of Briefing

*Generated by IPDebrief Intelligence Platform*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇫🇷 France
RegionDar es Salaam Region
CityMarseille
TimezoneEurope/Paris
Latitude-6.83
Longitude39.27

🏢 Ownership & Registration

OrganizationAdam L Mwaipungu
ASNAS33765
Network Name41.59.0.0 - 41.59.127.255
CIDR Block41.59.0.0/17
RIRAFRINIC
CountryTZ
Abuse Contact—

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)

🔐 DNS Hygiene

Hygiene Score0% (None)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECNot signed
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
ServerWeb server detected
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS33765
Network Prefix41.59.36.0/24
Route mappingFound
HSTSNot detected
CSPNot detected
HTTP/2Not detected

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
17%
23
routing
8%
11
services
23%
24
ownership
12%
22
reputation
8%
12
geolocation
25%
23
Overall15%1015
Coverage: 6/6 dimensions · Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) — 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: TZ, FR

📅 Observation Timeline 🔄 Live

First Seen2026-07-17 23:22:24 UTC
Last Seen2026-09-20 19:35:54 UTC
Profile Built2026-09-22 17:09:46 UTC
Data FreshnessLive
Signal Types19
Total Observations20
🔍 19 signal types · 20 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 41.59.36.228

Who owns the IP address 41.59.36.228?

41.59.36.228 is registered to Adam L Mwaipungu. The address falls within the 41.59.0.0/17 network block. Registration is held at AFRINIC.

Where is 41.59.36.228 located?

Geolocation data places 41.59.36.228 in Marseille, Dar es Salaam Region, France. The local time zone is Europe/Paris. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 41.59.36.228 malicious or safe?

41.59.36.228 currently carries a high risk assessment, meaning indicators associated with malicious or abusive activity have been observed. This assessment is generated from continuously collected signals and can change over time.

🏘️ Related IP Addresses

Nearby addresses in 41.59.0.0/17

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.