# IP Intelligence Briefing: 41.82.84.92/32
## Executive Summary
IP 41.82.84.92 presents a moderate risk profile (55/100) with significant geographic inconsistencies and DNS blacklist listings. The IP belongs to Alpha Mbodj (ASN 8346) but exhibits conflicting geolocation data between claimed US origin and observed Senegalese location. Despite showing no active services, the IP is listed on three DNS blacklists with high severity ratings.
---
## Technical Profile
Ownership & Registration:
- Organization: Alpha Mbodj
- ASN: 8346
- CIDR Block: 41.82.64.0/18 (41.82.64.0 - 41.82.127.255)
- RIR: AFRINIC
Geolocation Analysis:
- Claimed Location: New York, US
- Observed Location: Thiès, Senegal (14.7894°N, 16.926°W)
- Distance Discrepancy: 4,675.5 km from claimed location
- Minimum Possible RTT: 93.5ms vs observed 161.2ms average
Network State:
- Service Status: Firewalled / No Services (0 open ports)
- Network Role: Infrastructure not classified as CDN, hosting, proxy, or VPN
- DNS Status: No PTR records, no forward resolution
Threat Indicators:
- Blacklist Status: Listed on 3 of 8 DNS blacklists (high severity)
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Campaign Correlation: None identified
---
## Observation History (14 Observations)
Temporal Signals:
- Latest Activity: 2026-07-24T10:18:08 UTC
- Threat Persistence: 0 days observed
- Ownership Changes: 0
- Is Persistently Malicious: No
Anomaly Detection:
- Geolocation Inconsistency: Multiple conflicting country codes (US, SN) detected
- RTT Anomaly: Observed RTT exceeds minimum plausible RTT by 67.7ms
- DNSBL Listings: 3 DNS blacklist entries with high severity ratings
---
## Subnet Analysis
Subnet: 41.82.84.92/24
- Abuse Density: 0
- Classification: Clean
- Inherited Risk: 0
- Total Siblings: 1
- Active/Threat Siblings: 0
Relationship Graph:
- Only same-network relationships identified (41.82.64.0 - 41.82.127.255)
- No associated hostnames, organizations, or certificates detected
---
## Recommended Security Actions
Priority: High (Risk Score 55/100)
Monitoring:
- Increase logging verbosity for traffic from this IP
- Review recent activity patterns and connection attempts
Firewall Rules:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 41.82.84.92 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 41.82.84.92 drop` |
| nginx | `deny 41.82.84.92;` |
| pfSense | `41.82.84.92/32` |
| Cloudflare WAF | Block IP with expression `ip.src eq 41.82.84.92` |
| AWS WAF | Add IP `41.82.84.92/32` to block list |
---
## Intelligence Assessment
Key Risk Factors:
1. Geographic spoofing (claimed US, observed Senegal)
2. Multiple DNS blacklist entries despite no service exposure
3. Elevated risk score with no clear malicious activity pattern
Recommendations:
- Block at perimeter firewall pending additional correlation
- Monitor for any service emergence on this IP
- Verify if Alpha Mbodj is the legitimate owner or if this is misconfigured infrastructure
Confidence Level: Moderate – Requires correlation with traffic logs and incident data before definitive action.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Alpha Mbodj |
| ASN | AS8346 |
| Network Name | 41.82.64.0 - 41.82.127.255 |
| CIDR Block | 41.82.64.0/18 |
| RIR | AFRINIC |
| Country | SN |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS8346 |
| Network Prefix | 41.82.64.0/19 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 1 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 4% | 1 | 1 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-07 06:27:58 UTC |
| Last Seen | 2026-08-30 11:29:04 UTC |
| Profile Built | 2026-08-29 07:06:45 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 19 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 41.82.84.92
Who owns the IP address 41.82.84.92?
41.82.84.92 is registered to Alpha Mbodj. The address falls within the 41.82.64.0/18 network block. Registration is held at AFRINIC.
Where is 41.82.84.92 located?
Geolocation data places 41.82.84.92 in New York, US-NY, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 41.82.84.92 malicious or safe?
41.82.84.92 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.