# IP Intelligence Briefing: 41.89.227.161/32
## Executive Summary
IP 41.89.227.161 is classified as Low Risk (risk score: 15) with no active threat indicators. The address belongs to KENET Noc Team (ASN 36914) within the 41.89.227.0/24 block. While the IP shows no malicious indicators, it is DNSBL-listed on one of eight total lists and exhibits routing instability.
## Network Ownership & Classification
- ASN: 36914 (KENET Noc Team)
- Netname: 41.89.227.0 - 41.89.227.255
- RIR: afrinic
- Country: GB (geo consensus inconsistent with historical KE signals)
- Network Role: Firewalled / No Services
- Classification: Clean subnet, no active threat siblings
## Risk Assessment
The IP presents minimal threat:
- Risk Score: 15 (Low Risk)
- Threat Indicators: None detected
- Blacklist Count: 0 (despite DNSBL listing on 1 of 8 total lists)
- Reputation Sources: None
- Known Campaigns: None
- Tor Exit/Proxy/VPN: No
## Technical Observations
- Open Ports: None detected
- DNS: No PTR hostnames; forward resolution not confirmed
- Services: None active
- Control Plane: BGP prefix 41.89.227.0/24; route stability flagged as false; DNSSEC valid
- Trace Route: 18 hops; transit through Comcast and Cogent
## Neighborhood Analysis
The 41.89.227.0/24 subnet shows:
- Abuse Density: 0 (clean)
- Total Siblings: 2
- Active Siblings: 1
- Threat Siblings: 0
- Neighbor IP: 41.89.227.164 (risk score: 25, authority score: 50)
## Historical Context
Twelve observations recorded between 2026-07-28. Geolocation signals show inconsistency: recent probes identify Kenya (KE, Baricho, Kirinyaga County) while current profile shows GB. Operator score remains minimal (0.1304). No ownership changes or persistent threat activity observed.
## Recommended Actions
No specific firewall rules or mitigations recommended due to low risk profile. Standard network monitoring practices apply.
## Intelligence Narrative
The IP 41.89.227.161 represents a low-risk network endpoint with no active malicious behavior. While the subnet shows minimal abuse density, the single DNSBL listing and routing instability warrant routine monitoring. The neighbor IP 41.89.227.164 shows elevated authority score (50) but remains within acceptable parameters. No correlation to known threat campaigns or attacker infrastructure was identified.
Threat Level: Low
Monitoring Priority: Standard
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | KENET Noc Team |
| ASN | AS36914 |
| Network Name | 41.89.227.0 - 41.89.227.255 |
| CIDR Block | 41.89.227.0/24 |
| RIR | AFRINIC |
| Country | KE |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 22 | ssh | tcp | — |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | *.dkut.ac.kedkut.ac.ke |
| Valid From | 2026-03-18T00:00:00+00:00 |
| Valid Until | 2026-10-02T23:59:59+00:00 |
🛡️ Public Network Snapshot
| Origin ASN | AS36914 |
| Network Prefix | 41.89.227.0/24 |
| Route mapping | Found |
| Certificates in transparency logs | 0 certificates |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 25% | 2 | 4 |
| ownership | 25% | 2 | 3 |
| reputation | 20% | 1 | 3 |
| geolocation | 12% | 2 | 2 |
| Overall | 20% | 10 | 18 |
| Data Coherence | Mixed Signals (68%) — 2 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
⚠ TLS certificate claims KE but primary geo says GB
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-17 23:22:24 UTC |
| Last Seen | 2026-09-02 03:39:29 UTC |
| Profile Built | 2026-09-02 03:44:48 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 31 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 41.89.227.161
Who owns the IP address 41.89.227.161?
41.89.227.161 is registered to KENET Noc Team. The address falls within the 41.89.227.0/24 network block. Registration is held at AFRINIC.
Where is 41.89.227.161 located?
Geolocation data places 41.89.227.161 in London, Kirinyaga County, United Kingdom. The local time zone is Europe/London. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 41.89.227.161 malicious or safe?
41.89.227.161 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 41.89.227.161?
Responsive ports observed on 41.89.227.161 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.