IPDebrief

216.151.138.148

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 216.151.138.148

Classification: Moderate Risk Infrastructure IP

Analysis Date: Current

Risk Score: 40/100

## Executive Summary

IP address 216.151.138.148 belongs to Cisco Webex LLC (ASN 13445) and is geolocated to San Jose, California. The IP presents moderate risk (score 40) with no open services detected. While the immediate threat profile shows limited malicious activity, neighborhood analysis indicates mixed risk distribution within the /24 subnet.

## Infrastructure Profile

AttributeValue
**Organization**Cisco Webex LLC
**ASN**AS13445
**BGP Prefix**216.151.128.0/20
**Geolocation**San Jose, CA, US
**Network Role**Firewalled / No Services
**DNS Status**Forward resolution failed
**Route Stability**Stable (no changes in 30 days)

## Threat Indicators

## Neighborhood Analysis

Subnet: 216.151.138.148/24

MetricValue
**Total Siblings**256
**Active Siblings**161
**Threat Siblings**256
**Abuse Density**0.0 (Profile) / High Abuse Classification
**Risk Distribution**High: 0, Medium: 73, Low: 27

Key Observation: The subnet shows heterogeneous risk distribution with 73 medium-risk IPs and 27 low-risk IPs, despite the target IP scoring 40. This suggests the risk is isolated to specific addresses rather than subnet-wide.

## Observation History

Total Observations: 57

Recent signals indicate:

## Relationship Graph

Total Relationships: 173

## Recommended Security Actions

Despite moderate risk scoring, automated recommendations suggest blocking due to DNSBL presence and neighborhood risk factors.

Recommended Firewall Rules:

```bash

# iptables

iptables -A INPUT -s 216.151.138.148 -j DROP

# nftables

nft add rule inet filter input ip saddr 216.151.138.148 drop

# nginx

deny 216.151.138.148;

# pfSense

216.151.138.148/32

# Cloudflare WAF

ip.src eq 216.151.138.148 β†’ Block

# AWS WAF

Addresses: [216.151.138.148/32]

```

## Analyst Recommendations

1. Monitor, Don't Block Immediately: The IP shows moderate risk (40) with no active attack indicators. The Cisco Webex association suggests legitimate infrastructure.

2. Review DNSBL Listings: Investigate the 1 DNSBL listing to determine if it affects legitimate Webex traffic or represents a false positive.

3. Subnet Context: The /24 subnet shows mixed risk (73 medium, 27 low). Evaluate traffic patterns from related IPs in the 216.151.138.0/24 range.

4. Behavioral Monitoring: No honeypot hits, enumeration strikes, or WAF violations observed. Establish baseline traffic patterns for this ASN.

5. Historical Trend: 57 observations with stable ownership (0 changes). Threat persistence days: 0. No indication of escalating risk.

Final Assessment: Monitor for 7-14 days. Block only if traffic patterns indicate abuse or if DNSBL listing is confirmed as malicious. The IP appears to be legitimate Cisco infrastructure with elevated risk scoring due to neighborhood proximity to other flagged addresses.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionCA
CitySan Jose
Timezoneβ€”
Latitude37.75
Longitude-97.82

🏒 Ownership & Registration

OrganizationCisco Webex LLC
ASNAS13445
Network Nameβ€”
CIDR Block216.151.128.0/20
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierTier 3 β€” Basic operator with some routing infrastructure
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
28%
24
routing
25%
23
services
20%
23
ownership
22%
34
reputation
27%
13
geolocation
31%
23
Overall25%1220
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-07 23:05:10 UTC
Last Seen2026-06-26 18:12:07 UTC
Profile Built2026-06-27 01:56:50 UTC
Data FreshnessLive
Signal Types26
Total Observations55
πŸ” 26 signal types Β· 55 observations collected
This report is generated from 26+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.