# IP Intelligence Briefing: 172.216.11.33/32
Classification: Low Risk
Risk Score: 25/100
Date: 2026-07-28
## Executive Summary
The target IP 172.216.11.33 presents a low-risk profile with minimal threat indicators. The address is currently firewalled with no active services and demonstrates no malicious behavior in observation history.
## Network Profile
The IP belongs to subnet 172.216.11.0/24 under ASN 209854 (Cyberzonehub - Cyberzone S.A., PA). Geolocation data indicates New Jersey, US with RIR registration under ARIN. The organization name is listed as "Admin" with netname CYBERZONE-SA-US.
## Technical Observations
- Service Status: No open ports detected; service purpose classified as "Firewalled / No Services"
- DNS Resolution: No PTR record exists; forward resolution count is 0
- TLS/HTTP: No certificates or HTTP titles detected; HSTS, CSP, and HTTP/2 flags are absent
- Control Plane: BGP prefix 172.216.11.0/24; one DNSBL listing identified among 8 total lists
- Traceroute: 17 hops with transit through Comcast networks; 3 timeouts observed
- Behavioral Signals: Zero honeypot hits, enumeration strikes, or WAF violations
## Threat Indicators
- Blacklist Status: Listed on 1 of 8 DNSBLs with high severity classification in recent observations
- Malicious Activity: Not flagged as Tor exit node, known attacker, or spam source
- Campaign Association: No known campaign correlations; zero certificate matches
- Historical Threat Persistence: 0 threat observation days; not persistently malicious
## Neighborhood Analysis
The /24 subnet (172.216.11.0/24) shows zero neighbor IPs in the database. Abuse density is 0% with no high or medium-risk siblings detected. Risk distribution across the subnet is neutral.
## Relationship Graph
Single relationship detected: same network classification to CYBERZONE-SA-US. No additional organizational, hostname, or certificate associations.
## Recommended Actions
No specific firewall or blocking recommendations generated. The low risk score (25) and absence of active services indicate standard monitoring is appropriate. If the IP appears in active traffic analysis, allow traffic unless contextual indicators suggest otherwise.
## Monitoring Priority
Low. The IP demonstrates stable, benign characteristics with no observable malicious activity. Continue standard network monitoring practices.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Admin |
| ASN | AS209854 |
| Network Name | CYBERZONE-SA-US |
| CIDR Block | 172.216.11.0/24 |
| RIR | ARIN |
| Country | US |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 8443 | https-alt | tcp | — |
| Closed Ports | 22, 25, 80, 443, 3389, 8080 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS209854 |
| Network Prefix | 172.216.11.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 4% | 1 | 2 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-16 04:31:19 UTC |
| Last Seen | 2026-07-28 01:42:44 UTC |
| Profile Built | 2026-08-30 21:05:45 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 172.216.11.33
Who owns the IP address 172.216.11.33?
172.216.11.33 is registered to Admin. The address falls within the 172.216.11.0/24 network block. Registration is held at ARIN.
Where is 172.216.11.33 located?
Geolocation data places 172.216.11.33 in Phoenix, Arizona, United States. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 172.216.11.33 malicious or safe?
172.216.11.33 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 172.216.11.33?
Responsive ports observed on 172.216.11.33 include 8443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.