# Threat Intelligence Briefing: 216.151.137.79
## Executive Summary
IP address 216.151.137.79 is associated with Cisco Webex LLC (ASN 13445) and carries a moderate risk score of 49. The IP was identified as a known attacker and appears on blocklist.de. The address operates within the 216.151.128.0/20 BGP prefix in New York, US, and shows no active services or open ports.
## Technical Profile
Ownership: Cisco Webex LLC (ASN 13445), registered with ARIN. The IP belongs to the 216.151.137.0/24 subnet.
Geolocation: New York, United States. Multiple geolocation sources confirm US origin with consensus validation.
Network Classification: The IP is classified as "Firewalled / No Services" with no open ports detected. No TLS certificates, HTTP services, or banner information was observed.
DNS: No forward or reverse DNS resolution. No hosted domains or email authentication records (SPF, DMARC) were found.
Threat Indicators: The IP is flagged as a known attacker and is listed on one blacklist (blocklist.de). No active threat campaigns were correlated.
## Neighborhood Analysis
The 216.151.137.0/24 subnet was classified as "high_abuse" with an abuse density score of 1. Analysis of 100 neighboring IPs in the /24 revealed:
- High risk: 0 IPs
- Medium risk: 70 IPs
- Low risk: 30 IPs
Inherited risk from the subnet is 40, indicating the IP's risk is consistent with neighborhood patterns.
## Historical Observations
Forty-two observations were recorded for this IP. Recent observations from June 24, 2026, confirmed:
- ASN assignment to Cisco Webex LLC (95% confidence)
- BGP prefix 216.151.128.0/20 (85% confidence)
- Multiple threat signal pulses were detected
The IP shows persistent threat observation with 1 threat observation count recorded.
## Network Relationships
One hundred thirty-seven relationships were identified, primarily network-level associations to CS-1711. No organizational or hostname relationships were returned beyond network classifications.
## Recommended Actions
Given the moderate risk profile and known attacker designation, the following defensive measures are recommended:
1. Firewall Rules: Monitor and restrict outbound connections to this IP. The IP is not currently hosting services, so inbound blocking may be considered based on operational requirements.
2. IDS/IPS Signatures: Deploy signatures for traffic to/from 216.151.137.79 given its known attacker classification.
3. Threat Intelligence Feeds: Maintain this IP on blocklist.de for automated blocking.
4. Monitoring: Continue monitoring for service emergence or port opening, as the IP is currently in a firewalled state.
Risk Assessment: This IP represents a moderate threat requiring monitoring. The association with Cisco Webex LLC infrastructure suggests legitimate organizational ownership, but the known attacker flag and blacklist presence warrant defensive measures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Cisco Webex LLC |
| ASN | AS13445 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 3 | 3 |
| routing | 20% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 20% | 2 | 3 |
| reputation | 34% | 2 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 24% | 11 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:08 UTC |
| Last Seen | 2026-06-26 18:12:05 UTC |
| Profile Built | 2026-06-27 01:38:26 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 45 |
Full dossier details are available via our API.