## IP Intelligence Briefing: 216.152.249.139
Classification: Moderate Risk | Risk Score: 40 | Status: Firewalled / No Services
Executive Summary
IP address 216.152.249.139 is a residential/ISP-allocated address owned by Beamspeed LLC (ASN 14237) with a moderate risk profile. The IP shows no active threat indicators but is associated with a subnet exhibiting high abuse classification. Traffic should be filtered according to the recommended firewall rules.
Ownership and Geolocation
- Organization: Beamspeed LLC
- ASN: 14237
- Country: United States (Arizona)
- City: Yuma
- CIDR Block: 216.152.249.0/24
- Registration: ARIN
Network Role and Services
The IP is classified as "Firewalled / No Services" with no open ports detected. DNS resolution confirms the IP is assigned to a wireless service with PTR hostname `ip-216-152-249-139.wireless.dyn.beamspeed.net`. No TLS certificates, HTTP services, or reverse DNS anomalies were observed.
Threat Indicators
- Threat Indicators: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 total lists
Email Authentication
The associated domain `beamspeed.net` has properly configured email authentication:
- SPF: Configured (v=spf1 mx ip4:216.152.253.128/25 ~all)
- DMARC: Configured (p=quarantine)
Subnet Neighborhood Analysis
The /24 subnet (216.152.249.0/24) shows:
- Total Siblings: 256
- Active Siblings: 108
- Abuse Density: 0
- Classification: High Abuse
- Risk Distribution: High: 0, Medium: 35, Low: 65
Multiple neighboring IPs in the same subnet exhibit risk scores between 25-49, indicating potential systemic network-level issues.
Historical Observations
48 observations have been recorded. Recent signals include:
- DNS authentication records (SPF, DMARC) with confidence 0.85
- Operator scores consistently at 0.1304 (Minimal)
- No persistent malicious activity detected
Recommended Actions
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 216.152.249.139 -j DROP
# nftables
nft add rule inet filter input ip saddr 216.152.249.139 drop
# Cloudflare WAF
ip.src eq 216.152.249.139 β Block
# AWS WAF
Addresses: 216.152.249.139/32
```
Intelligence Narrative
This IP address represents a moderate risk residential/ISP endpoint. While the IP itself shows no active threat indicators or malicious behavior, it belongs to a subnet classified as high-abuse with multiple neighbors showing medium-level risk scores. The IP is properly configured with DNS and email authentication, and no services are actively running on the endpoint.
The recommended action is to implement filtering rules to block traffic from this address. However, given the moderate risk score (40) and the absence of confirmed threat indicators, SOC analysts should weigh this against business requirements before applying restrictive measures. The subnet-level context suggests potential neighbor correlation issues that may warrant broader subnet analysis if similar threat activity is observed.
Confidence Level: Moderate | Action Required: Filter/Block with business justification
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Beamspeed LLC |
| ASN | AS14237 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ip-216-152-249-139.wireless.dyn.beamspeed.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ip-216-152-249-139.wireless.dyn.beamspeed.net |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 27% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 23% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:12 UTC |
| Last Seen | 2026-06-26 18:12:09 UTC |
| Profile Built | 2026-06-27 07:48:36 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 51 |
Full dossier details are available via our API.