# IP Intelligence Briefing: 41.81.240.22
Classification: Moderate Risk • Status: Active • Date: Current
---
## Executive Summary
IP address 41.81.240.22 presents a moderate risk profile (Risk Score: 40) with ambiguous geolocation data and mobile carrier classification. The address exhibits geo-inconsistency between registration and observation data, and is currently blacklisted on 2 of 8 DNSBL feeds. No active threat indicators or known malicious campaigns have been identified. The subnet demonstrates clean abuse density characteristics.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **ASN** | 33771 |
| **Organization** | Domain Admin |
| **CIDR Block** | 41.81.0.0/16 |
| **RIR** | AFRINIC |
| **IP Type** | Mobile |
| **Mobile Carrier** | Safaricom PLC (KE) |
| **Reputation** | Moderate Risk (40/100) |
| **Open Ports** | None (Firewalled) |
| **DNSBL Listings** | 2 of 8 total |
---
## Geolocation Analysis
Critical Finding: Significant geo-inconsistency observed across data sources:
- Registration Data: AFRINIC registry associates block with Kenya (Nairobi)
- IP Profile Data: Reports United Kingdom (London)
- Mobile Carrier: Safaricom (Kenyan carrier, MCC: 639, MNC: 02)
- Historical Observations: Conflicting signals between KE and GB
This inconsistency suggests either misregistration, routing manipulation, or legitimate roaming behavior. The mobile carrier classification (Safaricom) strongly supports Kenyan origin.
---
## Threat Assessment
Current Risk Indicators:
- DNSBL listings present (2/8 feeds)
- Control plane stability: False (route changes observed)
- No active threat indicators
- No known attacker/spam source classification
- No Tor exit node activity
- No persistent malicious activity detected
Threat Persistence: 0 days • Campaign Correlation: None identified
---
## Neighborhood Analysis
Subnet: 41.81.240.22/24
- Abuse Density: 0 (Clean)
- Active Siblings: 0
- Threat Siblings: 0
- Neighbor Count: 0
The /24 subnet shows minimal risk characteristics with no immediate sibling threats.
---
## Historical Observations
14 signal observations recorded. Recent activity (2026-07-28) confirms:
- ICMP probing: Blocked/Unable to validate
- Ownership changes: 0
- Threat observation count: 0
No trend toward increased risk over observation period.
---
## SOC Recommendations
1. Monitor Geo-Discrepancy: Investigate conflicting geolocation data (KE vs GB) for potential routing anomalies or misconfiguration.
2. DNSBL Review: Evaluate the specific DNSBL feeds listing this IP to determine relevance to your threat context.
3. Mobile Classification: Treat as mobile IP with appropriate mobile network traffic policies.
4. No Immediate Action Required: No active malicious indicators detected. Standard logging and monitoring recommended.
5. Subnet Context: No threat correlation with neighboring IPs in /24 subnet.
---
## Actionable Firewall Rules
No specific blocking recommendations based on current risk profile. Standard logging and rate-limiting for mobile traffic recommended.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Domain Admin |
| ASN | AS33771 |
| Network Name | 41.81.0.0 - 41.81.255.255 |
| CIDR Block | 41.81.0.0/16 |
| RIR | AFRINIC |
| Country | KE |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS33771 |
| Network Prefix | 41.81.0.0/16 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-17 23:22:24 UTC |
| Last Seen | 2026-09-03 22:14:29 UTC |
| Profile Built | 2026-09-03 22:15:30 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 20 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 41.81.240.22
Who owns the IP address 41.81.240.22?
41.81.240.22 is registered to Domain Admin. The address falls within the 41.81.0.0/16 network block. Registration is held at AFRINIC.
Where is 41.81.240.22 located?
Geolocation data places 41.81.240.22 in London, Nairobi County, United Kingdom. The local time zone is Europe/London. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 41.81.240.22 malicious or safe?
41.81.240.22 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
Is 41.81.240.22 a VPN, proxy, or data center address?
41.81.240.22 is classified as a mobile network based on network ownership and behavioural analysis.