IPDebrief

216.151.137.79

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# Threat Intelligence Briefing: 216.151.137.79

## Executive Summary

IP address 216.151.137.79 is associated with Cisco Webex LLC (ASN 13445) and carries a moderate risk score of 49. The IP was identified as a known attacker and appears on blocklist.de. The address operates within the 216.151.128.0/20 BGP prefix in New York, US, and shows no active services or open ports.

## Technical Profile

Ownership: Cisco Webex LLC (ASN 13445), registered with ARIN. The IP belongs to the 216.151.137.0/24 subnet.

Geolocation: New York, United States. Multiple geolocation sources confirm US origin with consensus validation.

Network Classification: The IP is classified as "Firewalled / No Services" with no open ports detected. No TLS certificates, HTTP services, or banner information was observed.

DNS: No forward or reverse DNS resolution. No hosted domains or email authentication records (SPF, DMARC) were found.

Threat Indicators: The IP is flagged as a known attacker and is listed on one blacklist (blocklist.de). No active threat campaigns were correlated.

## Neighborhood Analysis

The 216.151.137.0/24 subnet was classified as "high_abuse" with an abuse density score of 1. Analysis of 100 neighboring IPs in the /24 revealed:

Inherited risk from the subnet is 40, indicating the IP's risk is consistent with neighborhood patterns.

## Historical Observations

Forty-two observations were recorded for this IP. Recent observations from June 24, 2026, confirmed:

The IP shows persistent threat observation with 1 threat observation count recorded.

## Network Relationships

One hundred thirty-seven relationships were identified, primarily network-level associations to CS-1711. No organizational or hostname relationships were returned beyond network classifications.

## Recommended Actions

Given the moderate risk profile and known attacker designation, the following defensive measures are recommended:

1. Firewall Rules: Monitor and restrict outbound connections to this IP. The IP is not currently hosting services, so inbound blocking may be considered based on operational requirements.

2. IDS/IPS Signatures: Deploy signatures for traffic to/from 216.151.137.79 given its known attacker classification.

3. Threat Intelligence Feeds: Maintain this IP on blocklist.de for automated blocking.

4. Monitoring: Continue monitoring for service emergence or port opening, as the IP is currently in a firewalled state.

Risk Assessment: This IP represents a moderate threat requiring monitoring. The association with Cisco Webex LLC infrastructure suggests legitimate organizational ownership, but the known attacker flag and blacklist presence warrant defensive measures.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionUS-NY
CityNew York
Timezoneβ€”
Latitude37.75
Longitude-97.82

🏒 Ownership & Registration

OrganizationCisco Webex LLC
ASNAS13445
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown β€” Insufficient routing data to classify
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
31%
33
routing
20%
11
services
8%
11
ownership
20%
23
reputation
34%
23
geolocation
31%
23
Overall24%1114
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-07 23:05:08 UTC
Last Seen2026-06-26 18:12:05 UTC
Profile Built2026-06-27 01:38:26 UTC
Data FreshnessLive
Signal Types17
Total Observations45
πŸ” 17 signal types Β· 45 observations collected
This report is generated from 17+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.