# IP INTELLIGENCE BRIEFING
Target: 216.152.249.222/32
Classification: Moderate Risk / Passive Infrastructure
Date: Current
Status: Active Monitoring
---
## EXECUTIVE SUMMARY
IP address 216.152.249.222 is a residential/modern infrastructure endpoint operating under Beamspeed LLC (ASN 14237) in Yuma, Arizona. The IP presents moderate risk (score: 40/100) with no active services detected. Despite the moderate overall risk rating, the /24 subnet (216.152.249.0/24) exhibits high abuse density classification, suggesting coordinated activity within the network block.
---
## NETWORK OWNERSHIP & GEOLOCATION
| Attribute | Value |
|---|---|
| **Organization** | Beamspeed LLC |
| **ASN** | 14237 |
| **Country/Region** | US / AZ (Yuma) |
| **CIDR Block** | 216.152.249.0/24 |
| **Registration** | ARIN |
| **Network Type** | Residential / Dynamic |
---
## THREAT INDICATORS
- Risk Score: 40 (Moderate)
- Provider Score: 0
- Authority Score: 0
- DNSBL Listings: 1 of 8 lists
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Campaign Association: None identified
Threat Assessment: No active threat indicators detected. The IP is not associated with known campaigns, malware, or malicious campaigns.
---
## SERVICE ANALYSIS
- Open Ports: None detected
- HTTP/HTTPS Services: No
- TLS Certificates: None
- Service Classification: Firewalled / No Services
- Network Role: Residential endpoint with no exposed services
---
## NEIGHBORHOOD ANALYSIS
Subnet: 216.152.249.0/24
| Metric | Value |
|---|---|
| **Abuse Density** | 1.0 (High) |
| **Classification** | high_abuse |
| **Total Siblings** | 256 |
| **Active Siblings** | 149 |
| **Threat Siblings** | 256 |
Risk Distribution in /24:
- High Risk: 0
- Medium Risk: 35
- Low Risk: 65
Notable Neighbors:
- 216.152.249.0 (Risk: 25)
- 216.152.249.1 (Risk: 25)
- 216.152.249.3 (Risk: 49)
- 216.152.249.4 (Risk: 49)
---
## OBSERVATION HISTORY
- Total Observations: 52
- Recent Activity: Consistent low-level monitoring signals
- Latest Signals: Minimal threat classification (operator score: 0.1304)
- Threat Persistence: 0 days (not persistently malicious)
- Ownership Stability: No recent ownership changes
The IP has maintained consistent low-to-minimal threat signatures across multiple observation windows with no escalation patterns detected.
---
## DNS & HOSTING ANALYSIS
- PTR Record: ip-216-152-249-222.wireless.dyn.beamspeed.net
- Hosted Domains: 0
- Email Auth: SPF enabled, DMARC status unknown
- FQDN Resolution: Active (1 confirmed hostname)
---
## RELATIONSHIP GRAPH
- Total Relationships: 338
- Primary Associations:
- DNS: ip-216-152-249-222.wireless.dyn.beamspeed.net
- Network: BEAMS
- Multiple DNS association entries (consistent pattern)
---
## CONTROL PLANE DATA
- BGP Prefix: 216.152.249.0/24
- Route Stability: Not stable
- RPKI State: Not assessed
- IRR Consistency: Not assessed
- Route Changes (30d): 0
- DNSSEC: Valid
- Operator Score: 0.3043 (Basic)
---
## RECOMMENDED ACTIONS
1. Monitor: Track IP activity for service changes or service openings
2. Block: Consider blocking if the IP initiates connections to internal resources
3. Observe: Monitor neighbor subnet (216.152.249.0/24) for coordinated activity patterns
4. Alert: Set up alerts for any service discovery or DNS changes
Firewall Rule Recommendation:
```
# Allow/Block based on organizational policy
# IP: 216.152.249.222
# Risk: Moderate (40) - No services detected
```
---
## INTELLIGENCE NARRATIVE
The IP 216.152.249.222 represents a dormant residential endpoint within a high-abuse-density subnet. While the individual IP shows no active services, malicious, or campaign-associated behavior, the surrounding /24 subnet demonstrates concerning abuse patterns with 256 threat-sibling IPs. The IP's moderate risk score reflects its location within this problematic subnet rather than intrinsic malicious characteristics.
The endpoint has not exhibited escalating threat behavior over the observation period, with consistent minimal threat signatures. However, the high abuse density of the parent subnet suggests this IP may be part of a larger compromised infrastructure or may have been utilized for abuse by associated entities.
Key Indicators for SOC Teams:
- Monitor for service openings on this IP
- Watch for connection attempts from this subnet to internal resources
- Correlate with other IPs in 216.152.249.0/24 for pattern analysis
- Consider broader subnet-level blocking if abuse patterns persist
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Beamspeed LLC |
| ASN | AS14237 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ip-216-152-249-222.wireless.dyn.beamspeed.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ip-216-152-249-222.wireless.dyn.beamspeed.net |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 23% | 2 | 4 |
| routing | 20% | 1 | 1 |
| services | 17% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 27% | 1 | 3 |
| geolocation | 28% | 2 | 3 |
| Overall | 22% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:13 UTC |
| Last Seen | 2026-06-26 18:12:09 UTC |
| Profile Built | 2026-06-27 07:40:19 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 53 |
Full dossier details are available via our API.