# IP Intelligence Briefing: 70.160.213.113/32
Classification: LOW RISK
Risk Score: 25/100
Date: 2026-06-26
Prepared for: SOC Analyst Team
## Executive Summary
IP address 70.160.213.113 belongs to Cox Communications infrastructure and is classified as low-risk with no active threat indicators. The IP is firewalled with no open services, resides in residential infrastructure, and operates within a clean subnet. Recommended action: NO IMMEDIATE ACTION REQUIRED.
---
## Infrastructure Profile
Ownership & Classification
- Organization: Cox Communications (ASN: 22773)
- Network Block: NETBLK-HR-RDC-70-160-0-0 / 70.160.0.0/15
- Registry: ARIN
- Network Role: Firewalled / No Services
- Infrastructure Type: Residential
Geolocation
- Country: United States (US)
- Region: Virginia (VA)
- City: Norfolk
- RTT Validation: Geographic inconsistency detected (38ms observed vs. 127.9ms minimum for 6,396km distance)
DNS Analysis
- PTR Hostname: ip70-160-213-113.hr.hr.cox.net
- Forward Resolution: Confirmed
- Domain: cox.net
- Email Authentication: SPF and DMARC records present
---
## Threat Assessment
Current Threat Indicators
- Blacklist Count: 0
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- VPN/Proxy: False
- Campaign Association: None identified
- Threat Feeds: No matches
Risk Breakdown
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
- Abuse Confidence: Not applicable (no threat signals)
---
## Neighborhood Analysis
Subnet: 70.160.213.113/24
Abuse Density: 0%
Classification: Clean
Active Neighbors: 0
Threat Siblings: 0
The immediate /24 subnet shows no abuse activity, with all sibling IPs classified as clean.
---
## Historical Observations (22 Total Signals)
Recent Activity (June 2026)
- 2026-06-26: Multiple observations indicate residential infrastructure classification with "Basic" operator score (0.2609)
- 2026-06-06: Mixed observations showing residential and non-residential classifications
- Geographic Consensus: Inconsistent across observations (plausible: false)
Temporal Stability
- Ownership Changes: 0
- Threat Persistence Days: 0
- Observation Count: 0
- Is Persistently Malicious: False
---
## Network Relationships
- DNS Associations: 23 entries (ip70-160-213-113.hr.hr.cox.net)
- Network Associations: NETBLK-HR-RDC-70-160-0-0
- External Entities: None (no organizations, certificates, or external IP relationships)
---
## Control Plane Data
- Origin ASN: 22773
- BGP Prefix: 70.160.0.0/15
- Route Stability: Stable (no route changes in 30 days)
- RPKI State: Unknown
- IRR Consistency: Unknown
- DNSSEC: Valid
- Route Changes (30d): 0
---
## Recommended Actions
Firewall/Network Rules
- No blocking required β IP classified as low-risk with no threat indicators
- Standard residential filtering applies if organization policy restricts residential IP ranges
Monitoring Recommendations
- No enhanced monitoring necessary
- Routine logging sufficient for compliance
Additional Context
The IP address is associated with Cox Communications residential infrastructure. The geographic RTT anomaly (38ms vs. 127.9ms minimum for Norfolk, VA) may indicate probe measurement error or misreported geolocation data. No actionable threat intelligence suggests this IP is not involved in malicious activity.
---
Intelligence Level: Complete
Data Confidence: Medium (geo inconsistency noted)
Threat Level: Low (Risk Score: 25)
Action Required: None
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Cox Communications |
| ASN | AS22773 |
| Network Name | NETBLK-HR-RDC-70-160-0-0 |
| CIDR Block | 70.160.0.0/15 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | β |
π DNS Intelligence
| PTR | ip70-160-213-113.hr.hr.cox.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ip70-160-213-113.hr.hr.cox.net |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User β Residential ISP endpoint |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 15% | 2 | 2 |
| routing | 24% | 2 | 3 |
| services | 8% | 1 | 1 |
| ownership | 30% | 3 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 20% | 11 | 14 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-12 09:41:38 UTC |
| Last Seen | 2026-06-26 17:24:42 UTC |
| Profile Built | 2026-06-26 17:42:40 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 30 |
Full dossier details are available via our API.