# IP Intelligence Briefing: 41.90.33.103/32
## Executive Summary
IP address 41.90.33.103 presents a low-risk profile (risk score: 25) with no evidence of active malicious activity. The address is associated with mobile device traffic from Safaricom in Nairobi, Kenya, and shows no open services or threat indicators. One adjacent IP in the /24 subnet (41.90.33.15) exhibits moderate risk characteristics.
## Ownership and Network Classification
- ASN: 33771 (Domain Admin)
- Organization: Domain Admin
- CIDR Block: 41.90.0.0 - 41.90.127.255 (/17)
- RIR: AFRINIC
- Network Role: Mobile device traffic
- Connection Type: LTE mobile (carrier: Safaricom PLC, MCC: 639, MNC: 02)
- Classification: Firewalled / No Services
## Geolocation Data
- Country: Kenya (KE)
- Region: Nairobi County
- City: Nairobi
- Coordinates: -1.28, 36.82
- Timezone: Africa/Nairobi
- Geo Validation: Plausible but ICMP validation blocked; distance from probe: 6,606 km
## Threat Intelligence Findings
- Risk Score: 25 (Low Risk)
- Abuse Confidence: Not applicable
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0
- DNSBL Listed: 1 out of 8 total lists
- Known Campaigns: None detected
- Operator Score: 0.1304 (Minimal)
## Network Services and DNS
- Open Ports: None detected
- TLS Certificate: None
- HTTP Title/Server Banner: None
- PTR Hostnames: None
- Forward Resolution: Not confirmed
- Hosted Domains: 0
- Email Authentication (SPF/DMARC): Not configured
## Control Plane Analysis
- Origin ASN: 33771
- BGP Prefix: 41.90.32.0/20
- Route Stability: False
- RPKI State: Not available
- DNSSEC Valid: True
- IRR Consistency: Not applicable
## Neighborhood Analysis (Subnet: 41.90.33.0/24)
- Abuse Density: 0
- Classification: Clean
- Total Siblings: 2
- Active Siblings: 0
- Threat Siblings: 0
- Notable Neighbor: 41.90.33.15 (risk score: 40, authority score: 50)
## Historical Observations (12 recorded signals)
- Threat Persistence Days: 0
- Ownership Changes: 0
- Persistent Malicious Activity: No
- Threat Observation Count: 0
- Last Observed: 2026-07-30
- Signal Types: Geolocation, routing, subnet classification, operator scoring
## Relationship Graph
- Same Network Relationships: 41.90.0.0 - 41.90.127.255 (3 entries)
- Organizational Links: None
- Hostname Associations: None
- Certificate Matches: None
## Recommended Actions
Based on the low-risk profile (score 25), no specific firewall or blocking rules are recommended. The IP shows no evidence of malicious behavior, no open services, and no persistent threat indicators.
Monitoring Priority: Low
Blocking Recommendation: Not required
Additional Investigation: Consider monitoring the sibling IP 41.90.33.15 (risk score 40) for potential correlation.
---
*Analysis generated using IPDebrief intelligence tools. Data reflects observations as of the latest signal collection.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Domain Admin |
| ASN | AS33771 |
| Network Name | 41.90.0.0 - 41.90.127.255 |
| CIDR Block | 41.90.0.0/17 |
| RIR | AFRINIC |
| Country | KE |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 1 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-26 15:20:45 UTC |
| Last Seen | 2026-07-30 08:40:25 UTC |
| Profile Built | 2026-07-30 08:58:11 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 15 |
Full dossier details are available via our API.