# IP Intelligence Briefing: 41.90.34.72/32
Classification: Low Risk | Risk Score: 0 | Date: 2026-07-30
## Executive Summary
IP address 41.90.34.72 is a mobile carrier-allocated endpoint (Safaricom, Kenya) with no observed malicious activity. The IP shows no open services, no blacklist presence, and zero threat indicators. Historical observation data indicates stable, benign behavior with no escalation in threat profile.
## Technical Profile
Ownership & Network
- ASN: 33771
- Organization: Domain Admin
- CIDR Block: 41.90.0.0/17
- RIR: AfriNIC
- Contact: No abuse contact published
Geolocation (Conflicting Signals)
- Primary Classification: Nairobi, Kenya (Mobile carrier data)
- Secondary Indicators: London, GB (geo data discrepancy noted)
- Carrier: Safaricom PLC (MCC: 639, MNC: 02)
- Technology: LTE
Network State
- Services: None detected (Firewalled / No Services)
- Open Ports: 0
- TLS/HTTP: No certificates, no web service banners
- DNS Resolution: No PTR records, no forward resolution
- Mobile Endpoint: Confirmed
## Threat Assessment
Risk Indicators
- Abuse Confidence Score: None
- Blacklist Count: 0
- Known Campaigns: 0
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Control Plane
- Operator Score: 0.1304 (Minimal)
- Route Stability: Inconsistent (flagged as not stable)
- DNSSEC Valid: Yes
- Route Changes (30d): 0
## Neighborhood Analysis
Subnet: 41.90.34.0/24
- Abuse Density: 0 (Clean)
- Total Siblings: 2
- Active Siblings: 0
- Threat Siblings: 0
Neighbor Alert:
- 41.90.34.135: Risk Score 30, Authority Score 50
- *Monitor for activity correlation*
## Observation History
Total Observations: 10 (as of 2026-07-30)
- Recent Signals: ASN registration, traceroute data, operator scoring, subnet classification
- Threat Persistence: 0 days
- Ownership Changes: 0
- Trend: Stable, no escalation detected
## Relationships
- Same Network: 41.90.0.0 - 41.90.127.255
- Certificates: None
- Correlated IPs: None identified
## Recommended Actions
Current Status: No firewall rules or mitigation actions required. IP shows no malicious indicators.
Monitoring Recommendations:
1. Monitor neighbor 41.90.34.135 (elevated risk score 30) for correlation with 41.90.34.72
2. Investigate geolocation discrepancy (Kenya mobile carrier vs. GB geolocation data)
3. Include in passive monitoring for future threat indicator emergence
---
Analysis Notes: This IP represents a mobile endpoint with no observable threat activity. The primary concern is the geolocation inconsistency between mobile carrier data (Kenya/Safaricom) and geolocation probes (GB/London), which may indicate data quality issues or misconfiguration. No immediate defensive action is warranted.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Domain Admin |
| ASN | AS33771 |
| Network Name | 41.90.0.0 - 41.90.127.255 |
| CIDR Block | 41.90.0.0/17 |
| RIR | AFRINIC |
| Country | KE |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 18% | 5 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-24 20:34:18 UTC |
| Last Seen | 2026-07-30 01:19:45 UTC |
| Profile Built | 2026-07-30 01:35:02 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 15 |
Full dossier details are available via our API.