IPDEBRIEF INTELLIGENCE BRIEFING
Target IP: 156.233.228.73/32
Date: 2026-07-28
Classification: LOW RISK
---
EXECUTIVE SUMMARY
The target IP address 156.233.228.73 presents a low-risk threat profile with a risk score of 25. The IP is currently firewalled with no active services or open ports detected. While classified as low-risk overall, the address shows limited DNSBL presence (1 out of 8 lists) with high-severity listing. No active malicious campaigns or attack patterns were observed during the assessment period.
---
THREAT PROFILE
The IP address maintains a reputation score of 25, categorized as "Low Risk." Risk indicators include:
- Threat Indicators: None detected. The IP is not classified as a known attacker, spam source, or Tor exit node.
- Blacklist Status: Listed on 1 of 8 DNSBLs with maximum severity rating of "high" as of 2026-07-28T23:24:12.
- Behavioral Signals: Zero honeypot hits, enumeration strikes, WAF violations, or total incidents recorded. The address is not flagged as an active attacker or auto-banned.
- Campaign Activity: No campaign likelihood, certificate matches, or correlated IPs identified.
---
NETWORK OWNERSHIP & INFRASTRUCTURE
- ASN: 401701 (Control Plane origin)
- BGP Prefix: 156.233.228.0/23
- Organization: No organization name or netname identified in available data.
- Infrastructure Type: Classified as firewalled with no services running. No cloud, CDN, VPN, proxy, or hosting services detected.
- DNS Configuration: No forward resolution confirmed, no PTR hostnames, and zero hosted domains.
---
GEOLOCATION ANALYSIS
- Reported Location: Los Angeles, California, United States (Region: CA)
- Timezone: America/Los_Angeles
- GeoValidation: Inconsistencies detected. GeoPlausible flag is false despite reported US location. Claimed coordinates (34.0544, -118.244) show a distance of 9,013.9 km from expected location, suggesting potential spoofing or reporting error.
- Routing Path: 17 hops with transit networks including Comcast and NTT.
---
NEIGHBORHOOD & RELATIONSHIP ANALYSIS
- Subnet: 156.233.228.0/24
- Abuse Density: 0 (no abuse activity detected in /24 subnet)
- Neighbor Count: 0 sibling IPs analyzed
- Relationship Graph: No relationships identified (no associated subnets, hostnames, organizations, or certificates)
---
OBSERVATION HISTORY
The IP has been observed 11 times since the earliest available signal. Key temporal findings:
- Most Recent Signal (2026-07-28T23:26:49): Geo signal with ICMP validation blocked; claimed coordinates in California.
- Operator Score (2026-07-28T23:24:35): Labeled "Minimal" with operator score of 0.1304.
- DNSBL Signal (2026-07-28T23:24:12): Listed on 1 of 8 DNSBLs with high-severity rating.
- Temporal Stability: No ownership changes detected. Threat persistence days: 0. Not persistently malicious.
---
SECURITY ACTIONS & RECOMMENDATIONS
Based on the risk profile, the following actions are recommended:
1. Monitoring: Continue passive monitoring. The low risk score (25) does not warrant immediate blocking.
2. DNSBL Watch: Monitor DNSBL listing status due to high-severity listing presence.
3. Geolocation Verification: Investigate geo inconsistencies if this IP is observed in traffic from unexpected regions.
4. Firewall Rules: No immediate firewall rules required. No services are open to exploit.
5. Threat Response: No immediate incident response required. No active attack patterns detected.
---
CONCLUSION
IP address 156.233.228.73/32 represents a low-risk network asset with no active malicious behavior observed. The single DNSBL listing with high severity warrants periodic review but does not indicate immediate threat. No related infrastructure, relationships, or neighborhood abuse activity was identified. Recommended classification: LOW RISK — MONITOR.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Cloud Innovation Support |
| ASN | AS401696 |
| Network Name | 156.233.228.0 - 156.233.228.255 |
| CIDR Block | 156.233.228.0/24 |
| RIR | ARIN |
| Country | US |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS401696 |
| Network Prefix | 156.233.228.0/22 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 17% | 2 | 3 |
| routing | 14% | 1 | 2 |
| services | 12% | 2 | 2 |
| ownership | 12% | 2 | 2 |
| reputation | 8% | 1 | 2 |
| geolocation | 17% | 2 | 3 |
| Overall | 13% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-20 00:17:00 UTC |
| Last Seen | 2026-09-02 20:24:55 UTC |
| Profile Built | 2026-09-02 20:25:59 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 26 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 156.233.228.73
Who owns the IP address 156.233.228.73?
156.233.228.73 is registered to Cloud Innovation Support. The address falls within the 156.233.228.0/24 network block. Registration is held at ARIN.
Where is 156.233.228.73 located?
Geolocation data places 156.233.228.73 in Los Angeles, California, United States. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 156.233.228.73 malicious or safe?
156.233.228.73 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.