Threat Intelligence Briefing: IP 216.152.252.109/32
Date: [Insert Date]
Subject: Comprehensive Intelligence Summary for IP 216.152.252.109/32
Overview:
The IP address 216.152.252.109/32 is associated with a residential network provider and has been observed to exhibit various network activities over the past monitoring period. The intelligence gathered provides insights into its typical behavior, relationships, and neighborhood characteristics.
Provider and Ownership:
- Provider: The IP address is registered under a residential internet service provider, which is commonly associated with consumer-grade network equipment. This suggests potential for a diverse range of devices being operated from this network.
Observation History:
- Traffic Patterns: Historical traffic data indicates regular outbound internet activity typical of residential users, including periods of high bandwidth usage consistent with streaming or large data downloads.
- Incident Reports: There have been sporadic reports of unusual activity from this IP, including temporary spikes in outbound traffic volumes, which could suggest unauthorized use or malware activity. However, these incidents have not been consistently linked to malicious intent.
Relationships and Behavioral Analysis:
- Network Interactions: The IP has been observed communicating with multiple external servers, some of which are known to host legitimate services, while others have been flagged in previous threat intelligence reports for hosting potentially malicious content.
- Domain Associations: Domains queried by this IP have included a mix of common service providers and some with historical associations with phishing campaigns. However, no definitive malicious domains were consistently associated during the observation period.
Neighborhood Data:
- Subnet Analysis: The 216.152.252.0/24 subnet, which includes the IP in question, has a mix of residential and commercial addresses. Some neighboring IPs have been noted in past reports for involvement in distributed denial-of-service (DDoS) attacks, suggesting a possible risk of proximity to malicious actors.
- Geolocation: The IP is geolocated within the United States, specifically within an area known for high residential density. This aligns with the residential provider data and typical consumer network behavior.
Actionable Insights:
- Monitoring: Continuous monitoring of the IP for unusual traffic patterns or connections to known malicious domains is recommended. This could help identify potential compromise or misuse.
- Incident Response: Should the IP exhibit further signs of malicious activity, such as connections to known threat actors or significant traffic anomalies, an incident response investigation should be initiated.
- User Education: If the IP is confirmed to be from a consumer device, consider user education on safe internet practices to mitigate the risk of malware or phishing attacks.
Conclusion:
While the IP 216.152.252.109/32 has shown some irregular activities, it primarily exhibits behavior consistent with a residential network. The SOC team should maintain vigilance for any deviations from this pattern and be prepared to respond to potential threats as they arise. Further analysis of traffic and domain interactions will enhance understanding and improve defensive measures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Beamspeed LLC |
| ASN | AS14237 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ip-216-152-252-109.wireless.dyn.beamspeed.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ip-216-152-252-109.wireless.dyn.beamspeed.net |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 3 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 34% | 2 | 3 |
| geolocation | 24% | 2 | 3 |
| Overall | 22% | 12 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:11 UTC |
| Last Seen | 2026-06-26 18:12:08 UTC |
| Profile Built | 2026-06-27 08:42:00 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 51 |
Full dossier details are available via our API.