# INTELLIGENCE BRIEFING: 41.84.225.2
Classification: MODERATE RISK | Date: [Current Date] | Analyst: IPDebrief SOC
---
## EXECUTIVE SUMMARY
IP 41.84.225.2 presents a moderate risk profile (score: 55) with no active malicious indicators currently detected. The address is associated with ASN 19711 (Musa Tsela) and located within the 41.84.225.0/24 subnet. While DNSBL listings indicate historical reputation concerns, the IP currently shows no open services, no Tor exit node activity, and no active threat signatures.
---
## OWNERSHIP & INFRASTRUCTURE
- ASN: 19711 (SWAZILAND PTC - SWAZILAND PTC, SZ)
- Organization: Musa Tsela
- CIDR Block: 41.84.225.0/24 (256 addresses)
- RIR Registration: AFRINIC
- BGP Prefix: 41.84.224.0/22
- Geolocation: United States, Florida, Miami (Note: ASN registration shows SZ/Swazilandβpotential routing discrepancy)
- Route Stability: Unstable (route changes detected)
---
## THREAT PROFILE
| Metric | Value |
|---|---|
| Risk Score | 55 (Moderate) |
| Blacklist Count | 0 |
| DNSBL Listings | 3 of 8 total lists |
| Known Attacker | No |
| Spam Source | No |
| Tor Exit Node | No |
| Open Ports | None detected |
| Active Services | None |
Threat Indicators: No active threat feeds or campaign correlations identified.
---
## NETWORK BEHAVIOR & SIGNALS
- Network Role: Firewalled / No Services
- Connection Type: Residential/Infrastructure classification pending
- Honeypot Hits: 0
- WAF Violations: 0
- Enumeration Strikes: 0
Recent Signal History (9 observations):
- DNSSEC validation confirmed (valid RRSIG)
- ASN/BGP signals from team-cymru-dns registry
- Blacklist activity with high-severity listings detected
- PTR record resolution: None
---
## NETWORK CONTEXT
Same Network Analysis (41.84.225.0/24)
- Total Siblings: 256 (in /24)
- Active Siblings: 0
- Abuse Density: 0
- Risk Distribution: High: 0, Medium: 0, Low: 0
Neighboring IP Analysis
- Subnet: 41.84.225.2/24
- Neighbor Count: 0
- Related Entities: Same network relationship only
---
## NETWORK TRACEROUTE
- Hop Count: 30
- First Hop RTT: 0.3ms
- Last Hop RTT: 56.4ms
- Transit Networks: Comcast, Lumen
- Timed Out Hops: 23 (significant routing variation)
---
## RECOMMENDED ACTIONS
Firewall Rules
```bash
# Allow basic connectivity (no active blocking required)
# Monitor for service emergence
```
SOC Monitoring Priorities
1. Service Scanning: IP currently shows no open servicesβmonitor for port opening
2. Geolocation Discrepancy: Investigate US vs SZ registration mismatch
3. DNSBL Activity: Review 3 blacklist listings for context
4. Route Stability: Track BGP prefix changes for potential infrastructure shifts
Risk Assessment
- Immediate Threat: Low
- Long-term Concern: Moderate (unstable routing, blacklist history)
- Recommended Action: Monitorβno immediate blocking required
---
## CONCLUSION
IP 41.84.225.2 represents a moderate-risk infrastructure address with no active malicious indicators. The network is currently quiet (no open services), but the combination of unstable routing, DNSBL listings, and geolocation inconsistencies warrants continued observation. SOC teams should monitor for service emergence and investigate the US/Swaziland registration discrepancy during routine intelligence cycles.
Classification: DEFENSIVE INTELLIGENCE | Status: MONITOR
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Musa Tsela |
| ASN | AS19711 |
| Network Name | 41.84.225.0 - 41.84.225.255 |
| CIDR Block | 41.84.225.0/24 |
| RIR | AFRINIC |
| Country | SZ |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 1 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 4% | 1 | 1 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-24 08:18:48 UTC |
| Last Seen | 2026-07-29 22:43:38 UTC |
| Profile Built | 2026-07-29 22:49:35 UTC |
| Data Freshness | Live |
| Signal Types | 11 |
| Total Observations | 11 |
Full dossier details are available via our API.