# IP Intelligence Briefing: 41.90.141.82/32
## Executive Summary
IP 41.90.141.82 presents as a low-risk mobile device endpoint with no active threat indicators. The address belongs to a mobile carrier infrastructure under Safaricom PLC (Kenya) but with geolocation inconsistencies pointing to London, UK. No immediate defensive action is required based on current data.
## Risk Assessment
- Overall Risk Score: 25/100 (Low Risk)
- Provider Score: 0 (No provider infrastructure detected)
- Authority Score: 0
- Stability Score: 0
- Classification: Mobile device, firewalled/no services
## Network Ownership & Registration
- ASN: 33771
- Organization: Domain Admin
- Network Block: 41.90.128.0/17 (41.90.128.0 - 41.90.255.255)
- RIR Registry: AFRINIC
- Abuse Contact: Not available
## Geolocation Intelligence
- Reported Country: GB (UK)
- Region/City: Nairobi County, London
- Mobile Carrier: Safaricom PLC (MCC 639, MNC 02)
- Inferred Location: Kenya (based on mobile carrier data)
- Note: Geographic inconsistencies detected (6,606 km distance suggests data validation issues)
## Threat Indicators
- Abuse Confidence Score: Not assigned
- Blacklist Status: Clean (0 blacklists)
- DNSBL Status: Listed on 1 of 8 threat feeds
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Threat Campaigns: None identified
## Service Analysis
- Open Ports: None detected
- TLS Certificates: None
- HTTP Services: None
- Service Purpose: Firewalled / No Services
## Neighborhood Analysis (41.90.141.0/24)
- Subnet Abuse Density: 0 (Clean)
- Total Siblings: 7 IPs in /24
- Active Siblings: 1
- Threat Siblings: 0
- Risk Distribution:
- Low Risk: 6 IPs
- Medium Risk: 0 IPs
- High Risk: 0 IPs
Notable Neighbors:
- 41.90.141.18 (Risk: 25, Authority: 50)
- 41.90.141.219 (Risk: 25, Authority: 50)
- 41.90.141.246 (Risk: 25, Authority: 50)
## Control Plane Intelligence
- Origin ASN: 33771
- BGP Prefix: 41.90.141.0/24
- Route Stability: False (routing changes detected)
- DNSSEC: Valid
- Operator Score: 0.1304 (Minimal)
- Route Changes (30d): 0
## Historical Observation (Last 14 Observations)
Recent observations show consistent low-risk classification:
- Abuse Density: 0 across all observations
- Network Classification: Clean
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Not Persistently Malicious: Confirmed
## Recommended Actions
No firewall rules or blocking actions recommended. The IP exhibits characteristics of a legitimate mobile endpoint with no active threat indicators.
## Intelligence Notes for SOC Analysts
1. Mobile Endpoint: The IP is classified as a mobile device (Safaricom carrier), not infrastructure or hosting.
2. Low Risk Profile: Risk score of 25 with no threat indicators supports allowing traffic.
3. Geographic Discrepancy: Consider validating actual location against network logs, as geolocation data shows inconsistencies (GB vs KE).
4. Subnet Context: The broader /24 subnet shows minimal abuse density, supporting benign classification.
5. No Active Services: Firewalled with no detectable open ports or web services.
Final Assessment: Allow traffic. Monitor if this IP begins exhibiting anomalous behavior or if additional threat indicators emerge.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Domain Admin |
| ASN | AS33771 |
| Network Name | 41.90.128.0 - 41.90.255.255 |
| CIDR Block | 41.90.128.0/17 |
| RIR | AFRINIC |
| Country | KE |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS33771 |
| Network Prefix | 41.90.141.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 1 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 5 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-12 08:51:57 UTC |
| Last Seen | 2026-07-27 01:12:01 UTC |
| Profile Built | 2026-08-30 15:56:14 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 19 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 41.90.141.82
Who owns the IP address 41.90.141.82?
41.90.141.82 is registered to Domain Admin. The address falls within the 41.90.128.0/17 network block. Registration is held at AFRINIC.
Where is 41.90.141.82 located?
Geolocation data places 41.90.141.82 in London, Nairobi County, United Kingdom. The local time zone is Europe/London. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 41.90.141.82 malicious or safe?
41.90.141.82 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
Is 41.90.141.82 a VPN, proxy, or data center address?
41.90.141.82 is classified as a mobile network based on network ownership and behavioural analysis.