The IP address 128.109.9.22/32 was assessed as low risk with a score of 25. Ownership records identified the address as belonging to MCNC (NCREN) under ASN 81, registered in the US region of North Carolina. The host was observed to be firewalled with no open ports or active services running. DNS records pointed to ws-gw-to-hntvl-gw.ncren.net, with SPF validation enabled but lacking DMARC policies.
Threat intelligence scans detected zero blacklisting and no association with known attacker campaigns or specific threat actors. The local neighborhood (128.109.9.0/24) was classified as mostly clean with an abuse density of 0.5, though one threat sibling was recorded within the subnet.
Geolocation analysis presented a contradiction. While the location was registered as Lenoir, North Carolina, RTT measurements indicated a distance of 6811 km, which violated the minimum possible physics for that geographic coordinate. Attribution confidence was moderate at 70% based on ownership consistency. Behavioral analysis confirmed no enumeration strikes or honeypot hits. The recommendation was to monitor the asset due to signal contradictions, maintaining a low severity rating.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | MCNC |
| ASN | AS81 |
| Network Name | NCREN |
| CIDR Block | 128.109.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ws-gw-to-hntvl-gw.ncren.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ws-gw-to-hntvl-gw.ncren.net |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 2/2 domains |
| DMARC | 0/2 domains |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Present |
| Domains Checked | 2 domains |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 6 |
| routing | 30% | 3 | 4 |
| services | 19% | 2 | 2 |
| ownership | 35% | 3 | 5 |
| reputation | 27% | 1 | 5 |
| geolocation | 36% | 2 | 7 |
| Overall | 30% | 13 | 29 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-29 10:46:44 UTC |
| Last Seen | 2026-09-24 16:32:42 UTC |
| Profile Built | 2026-09-24 16:44:29 UTC |
| Data Freshness | Live |
| Signal Types | 31 |
| Total Observations | 52 |
Full dossier details are available via our API.