# IP Intelligence Briefing: 216.152.252.87/32
Classification: Moderate Risk β Known Attacker Activity
Date: 2026-06-24
Risk Score: 49/100
## Executive Summary
IP 216.152.252.87 is registered to Beamspeed LLC (ASN 14237) and is flagged as a known attacker with one active blacklist listing. The IP is associated with the 216.152.252.0/24 subnet, which exhibits high abuse density. Recommended action: Block or rate-limit at network edge.
## Ownership & Network Context
- Organization: Beamspeed LLC
- ASN: 14237 (Beamspeed LLC)
- BGP Prefix: 216.152.248.0/21
- Location: Yuma, Arizona, US (geolocation consensus confirmed)
- DNS Host: ip-216-152-252-87.wireless.dyn.beamspeed.net (forward/reverse confirmed)
- Email Auth: SPF and DMARC records present
## Threat Indicators
- Known Attacker: YES
- Blacklist Status: Listed on blocklist.de
- Blacklist Count: 1
- Tor Exit/Proxy/VPN: No
- Hosting/Cloud: No (classified as Firewalled / No Services)
- Abuse Confidence: Elevated based on known attacker flag
## Network Neighborhood Assessment
The /24 subnet (216.152.252.0/24) shows elevated abuse characteristics:
- Subnet Classification: High abuse
- Active Siblings: 139 out of 256 total IPs
- Abuse Density: 1.0
- Risk Distribution: 58 medium-risk, 42 low-risk, 0 high-risk neighbors
This suggests the subnet may be underutilized or experiencing elevated activity patterns.
## Historical Signal Analysis
46 observations recorded. Recent signal pattern shows:
- High-severity blacklist listing detected at 17:01 UTC (confidence 0.85)
- Multiple minimal-risk observations throughout the day (confidence 0.30)
- Threat observation count: 1
- Persistent malicious activity: No
## Recommended Security Actions
Action: Block or rate-limit at network edge
Severity: High
Reason: Suspicious activity indicators present
Firewall Rules (Recommended)
- iptables: `iptables -A INPUT -s 216.152.252.87 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 216.152.252.87 drop`
- nginx: `deny 216.152.252.87;`
- pfSense: `216.152.252.87/32`
- Cloudflare WAF: Block IP with expression `ip.src eq 216.152.252.87`
- AWS WAF: Apply rule to `216.152.252.87/32`
## Intelligence Assessment
The IP demonstrates attacker-related behavior with active blacklist presence. While no open ports were detected, the known attacker classification and blacklist listing warrant defensive blocking. The subnet context (high abuse density) supports the risk profile. Monitor for correlation with other Beamspeed LLC infrastructure or related malicious campaigns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Beamspeed LLC |
| ASN | AS14237 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ip-216-152-252-87.wireless.dyn.beamspeed.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ip-216-152-252-87.wireless.dyn.beamspeed.net |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 37% | 3 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 34% | 2 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 24% | 12 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:11 UTC |
| Last Seen | 2026-06-26 18:12:07 UTC |
| Profile Built | 2026-06-27 08:45:24 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 50 |
Full dossier details are available via our API.