# IP Intelligence Briefing: 216.152.252.231
Classification: Threat Intelligence
Date: Current
Analyst: IPDebrief Intelligence
---
## Executive Summary
IP 216.152.252.231 is a residential ISP address from Beamspeed LLC (ASN 14237) with a risk score of 49 (Moderate Risk). The IP is marked as a known attacker, listed on 1 blacklist (blocklist.de), and operates within a subnet classified as high abuse. SOC analysts should consider blocking or rate-limiting traffic from this address.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **IP Address** | 216.152.252.231/32 |
| **Risk Score** | 49 (Moderate Risk) |
| **ASN** | 14237 |
| **Organization** | Beamspeed LLC |
| **Location** | Yuma, AZ, US |
| **Known Attacker** | YES |
| **Blacklist Count** | 1 (blocklist.de) |
| **Network Role** | Firewalled / No Services |
| **DNS** | ip-216-152-252-231.wireless.dyn.beamspeed.net |
---
## Threat Indicators
- Primary Threat: Listed attacker with active blacklisting
- Risk Breakdown: Provider score 0, Authority score 0, Stability score 0
- Threat Feeds: blocklist.de
- Control Plane: BGP prefix 216.152.248.0/21, origin ASN 14237
---
## Neighborhood Analysis
Subnet 216.152.252.0/24 shows elevated threat density:
- Abuse Density: 1 (High)
- Classification: high_abuse
- Active Siblings: 157/256
- Threat Siblings: 256 (100% of monitored IPs show threat indicators)
- Neighbor Risk Distribution: Medium (46), Low (54), High (0)
Multiple sibling IPs within /24 share similar risk profiles (risk scores 25-49), suggesting coordinated residential ISP activity in this subnet.
---
## Historical Observations
Total: 45 observations recorded
- Latest Signal: 2026-06-24 (blacklist listings, risk assessments)
- Operator Score Range: 0.00 - 0.26
- Signal Consistency: Persistent monitoring with recurring blacklist checks
- Threat Persistence: Non-persistent malicious activity detected
---
## Recommended Actions
Immediate Actions Required:
1. Block or rate-limit at network edge (High Severity)
2. Implement firewall rules across infrastructure platforms
Platform-Specific Rules:
iptables:
```
iptables -A INPUT -s 216.152.252.231 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 216.152.252.231 drop
```
nginx:
```
deny 216.152.252.231;
```
Cloudflare WAF:
```
Action: block
Expression: ip.src eq 216.152.252.231
```
AWS WAF:
```
Addresses: 216.152.252.231/32
Description: IPDebrief risk 49
```
---
## Intelligence Narrative
This IP represents a residential ISP address from Beamspeed LLC with confirmed malicious indicators. The address has been blacklisted and is flagged as a known attacker. Given the high-abuse classification of the parent subnet and the 100% threat sibling rate, this IP should be treated as part of a broader threat landscape rather than an isolated anomaly.
The residential ISP nature of this address (dynamic DNS hostname, no open services detected) suggests the IP may be used for residential-based attacks, botnet command and control, or compromised residential infrastructure. SOC teams should monitor for associated IPs within the 216.152.252.0/24 subnet and consider implementing broader subnet-level filtering if business justification permits.
Recommendation: Implement blocking or rate-limiting rules. Monitor for pattern matching with other IPs in the 216.152.0.0/16 space.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Beamspeed LLC |
| ASN | AS14237 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ip-216-152-252-231.wireless.dyn.beamspeed.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ip-216-152-252-231.wireless.dyn.beamspeed.net |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 3 | 3 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 20% | 2 | 3 |
| reputation | 34% | 2 | 3 |
| geolocation | 24% | 2 | 3 |
| Overall | 22% | 11 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:12 UTC |
| Last Seen | 2026-06-26 18:12:08 UTC |
| Profile Built | 2026-06-27 08:17:08 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 47 |
Full dossier details are available via our API.