# INTELLIGENCE BRIEFING: 41.90.145.188/32
Date: 2026-07-30
Classification: Standard
Analyst: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
IP address 41.90.145.188 was assessed as low risk (risk score: 25) with no active threat indicators. The address exhibits firewalled behavior with no open services detected. While the subnet (41.90.145.0/24) shows mixed characteristics, the target IP itself presents minimal immediate threat to network infrastructure.
---
## PROFILE ANALYSIS
Risk Assessment:
- Overall Risk Score: 25 (Low Risk)
- Reputation Classification: Low Risk
- Operator Score: Minimal (0.1304)
- Not classified as Tor exit, proxy, CDN, or hosting infrastructure
Network Characteristics:
- Control Plane Origin ASN: 33771
- BGP Prefix: 41.90.145.0/24
- Routing Status: Not route-stable
- DNSSEC: Valid
- Route Changes (30d): 0
Geolocation Data:
- Country: Great Britain (GB)
- City: London
- Timezone: Europe/London
- Geographic Consensus: Inconsistent (multiple data sources showing conflicting region assignments)
Service Status:
- Open Ports: None detected
- TLS Certificate: Not configured
- HTTP/HTTPS: No services responding
- Connection Type: Firewalled / No Services
---
## THREAT INDICATORS
Current Threat Posture:
- Abuse Confidence Score: Not applicable
- Blacklist Count: 1 listing (of 8 total DNSBL checks)
- Known Campaigns: None detected
- Threat Feeds: No matches
- Known Attacker Status: Negative
Historical Activity (9 observations):
Recent observations on 2026-07-30 indicated:
- Port scanning activity detected
- DNSSEC validation confirmed
- DNSBL listing with maximum severity: High
- Operator classification: Minimal risk
---
## NEIGHBORHOOD ANALYSIS
Subnet 41.90.145.0/24 Assessment:
- Total Siblings: 5
- Abuse Density: 0
- Inherited Risk: 0
- Classification: Clean subnet
Neighbor Risk Profile:
| IP Address | Risk Score | Risk Category |
|---|---|---|
| 41.90.145.35 | 0 | Low |
| 41.90.145.62 | 25 | Low |
| 41.90.145.100 | 40 | Medium |
| 41.90.145.218 | 25 | Low |
| 41.90.145.222 | 55 | Medium |
Notable Neighbor Characteristics:
- 41.90.145.100 and 41.90.145.222 associated with mobile carrier Safaricom PLC
- Both neighbors show "Mobile" network role classification
- 41.90.145.222 exhibits highest neighborhood risk (score: 55) with 3 DNSBL listings
---
## RELATIONSHIP GRAPH
No relationships detected between 41.90.145.188 and:
- Related subnets
- Hostnames
- Organizations
- SSL Certificates
---
## TEMPORAL ANALYSIS
Stability Indicators:
- Ownership Changes: 0
- Average Ownership Duration: Not applicable
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Persistently Malicious: False
Route Stability:
- BGP Prefix Changes (30d): 0
- MOAS Status: Not applicable
- RPKI State: Not available
---
## RECOMMENDED ACTIONS
Immediate Actions:
- No specific firewall rules recommended based on current risk profile
- Low-risk classification precludes aggressive blocking
Monitoring Priorities:
1. Monitor 41.90.145.188 for risk score escalation
2. Track DNSBL listing status changes
3. Observe neighbor 41.90.145.222 (risk: 55) for activity patterns
4. Verify geographic consistency across data sources
Firewall Rules: None required at this time
---
## CONCLUSION
IP address 41.90.145.188 presents minimal threat to defensive security operations. The address demonstrates firewalled behavior with no active services and a single DNSBL listing. While the /24 subnet contains neighbors with elevated risk scores (particularly 41.90.145.222 at score 55), the target IP itself shows no persistent malicious behavior. Standard monitoring protocols are sufficient; no immediate blocking or mitigation actions are warranted.
Confidence Level: Low (0.1304 operator score indicates limited data sufficiency)
---
*This intelligence briefing was generated using IPDebrief threat intelligence tools. All data reflects observations as of 2026-07-30.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Domain Admin |
| ASN | AS33771 |
| Network Name | 41.90.128.0 - 41.90.255.255 |
| CIDR Block | 41.90.128.0/17 |
| RIR | AFRINIC |
| Country | KE |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-25 21:00:58 UTC |
| Last Seen | 2026-07-30 05:38:08 UTC |
| Profile Built | 2026-07-30 05:47:40 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 15 |
Full dossier details are available via our API.