# IP Intelligence Briefing: 173.239.214.152/32
Classification: LOW RISK
Report Date: 2026-07-30
Analyst: IPDebrief Intelligence Unit
## Executive Summary
IP address 173.239.214.152 is classified as Low Risk with a risk score of 25. The address is assigned to LOGICWEB (ASN 62240) within the 173.239.214.0/24 CIDR block. No active threat indicators, malware, or campaign associations were detected. The IP exhibits minimal operational activity and no open services.
## Ownership and Network Context
| Attribute | Value |
|---|---|
| **Organization** | Private Customer |
| **Netname** | LOGICWEB |
| **ASN** | 62240 |
| **CIDR Block** | 173.239.214.0/24 |
| **RIR** | ARIN |
| **Geolocation** | US, New Jersey, Edison |
| **Control Plane** | Route stable (isRouteStable: false) |
The IP is configured as "Firewalled / No Services" with no detected open ports or TLS certificates. DNS resolution shows no hosted domains, PTR records, or email authentication configurations (SPF/DMARC absent).
## Threat Assessment
Threat Indicators: None
Known Attacker: No
Spam Source: No
Tor Exit Node: No
Blacklist Count: 0
Abuse Confidence: Not scored
The control plane shows 1 DNSBL listing against 8 total lists. RPKI validation and IRR consistency data were not validated. No known threat campaigns or correlated IPs were identified.
## Neighborhood Analysis
The /24 subnet 173.239.214.152/24 exhibits a mostly_clean classification with the following characteristics:
- Abuse Density: 0.1014 (low)
- Total Siblings: 148
- Active Siblings: 89
- Threat Siblings: 15
- Inherited Risk Score: 4
Risk distribution across neighbors: 0 high-risk, 15 medium-risk, 85 low-risk. Notable sibling IPs include 173.239.214.6 and 173.239.214.7 (risk score: 40).
## Observation History
Twelve observations recorded as of 2026-07-30. Key temporal findings:
- No ownership changes detected
- No persistent malicious activity
- Threat observation count: 0
- Average ownership duration: Not applicable
- Threat persistence days: 0
## Geovalidation Discrepancy
Critical Finding: Significant geolocation validation failure detected.
- Claimed Location: US, New Jersey (40.52°N, -74.41°W)
- Observed RTT: 20ms average
- Minimum Possible RTT: 120.2ms for 6,008.1km distance
- Distance Violation: 6,008.1km
- Geo Plausible: False
- Confidence: 0.35 (low)
This RTT violation indicates the claimed geolocation is implausible. The IP is likely misconfigured or the geolocation data source is unreliable.
## Security Recommendations
No specific firewall rules or actions were generated. The IP presents minimal immediate threat, but analysts should:
1. Monitor Geovalidation: The RTT anomaly warrants periodic revalidation
2. Contextual Monitoring: Consider monitoring the subnet due to 15 identified threat siblings
3. Baseline Establishment: No open services detected; monitor for service emergence
## Risk Conclusion
IP 173.239.214.152 represents low operational risk with no active threat indicators. The primary concern is geolocation data integrity. Standard defensive posture is recommended without immediate blocking actions.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Private Customer |
| ASN | AS62240 |
| Network Name | LOGICWEB |
| CIDR Block | 173.239.214.0/24 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 1 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 5 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-27 15:46:21 UTC |
| Last Seen | 2026-07-30 12:50:52 UTC |
| Profile Built | 2026-07-30 13:04:33 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.