# IP Intelligence Briefing: 72.204.189.223/32
## Executive Summary
The IP address 72.204.189.223 presents a low-risk profile with a risk score of 25. The address is assigned to Cox Communications (AS22773) and is classified as a residential endpoint located in New Orleans, Louisiana. No active threat indicators or malicious campaigns were identified during the analysis period.
## Ownership and Network Classification
- Organization: Cox Communications, Inc.
- ASN: 22773
- Network Block: 72.204.128.0/18
- Geolocation: United States, Louisiana, New Orleans
- Classification: Residential
- Network Role: Firewalled / No Services
- RIR: ARIN
## Risk Assessment
- Overall Risk Score: 25 (Low Risk)
- Provider Score: 0
- Authority Score: 0
- Threat Indicators: None identified
- Blacklist Status: Not listed (0/0)
- DNSBL Listed: 1 of 8 lists
- Known Attacker: No
- Tor Exit Node: No
- Proxy/VPN Service: No
## Threat Intelligence Observations
The IP has generated 22 historical observations across the monitoring period. Key findings include:
- Observation Count: 22 signals recorded
- Recent Activity: Most recent observations recorded on 2026-06-25
- Threat Persistence: Single threat observation noted on 2026-06-05
- Persistent Malicious Activity: No
- Ownership Stability: No ownership changes detected
The observation history indicates a stable residential endpoint with minimal threat exposure.
## Neighborhood Analysis
- Subnet: 72.204.189.0/24
- Abuse Density: 0
- Neighbor Classification: Clean
- High-Risk Neighbors: 0
- Medium-Risk Neighbors: 0
- Low-Risk Neighbors: 0
The surrounding /24 subnet shows no abuse activity, reinforcing the low-risk classification of this address.
## Relationship Graph
The IP maintains 28 relationships, predominantly DNS associations and network block references. All relationships point to:
- Hostname: ip72-204-189-223.no.no.cox.net
- Network Block: NETBLK-NO-RDC-72-204-128-0
No external organizations, hostnames, or certificate associations were identified outside of Cox Communications infrastructure.
## DNS and Service Profile
- PTR Record: ip72-204-189-223.no.no.cox.net
- Forward Resolution: Confirmed
- Open Ports: None
- TLS Certificates: None
- HTTP Services: None detected
- Email Auth: SPF and DMARC records present
## Recommended Actions
Based on the low-risk profile, no immediate blocking or mitigation actions are recommended. The IP should be permitted through standard firewall rules with normal monitoring. The residential nature and clean neighborhood classification suggest this is a legitimate consumer endpoint.
## Analyst Notes
This IP address represents a standard residential connection from Cox Communications with no indicators of compromise. The single DNSBL listing appears to be a false positive or non-malicious listing. No correlation to known campaigns or attack infrastructure was identified. Continued monitoring is appropriate but no immediate action is warranted.
---
Classification: Intelligence Summary
Generated: 2026-06-25
Risk Level: Low
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Cox Communications |
| ASN | AS22773 |
| Network Name | NETBLK-NO-RDC-72-204-128-0 |
| CIDR Block | 72.204.128.0/18 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | β |
π DNS Intelligence
| PTR | ip72-204-189-223.no.no.cox.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ip72-204-189-223.no.no.cox.net |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User β Residential ISP endpoint |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 22% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 18% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-10 04:12:17 UTC |
| Last Seen | 2026-06-25 23:27:37 UTC |
| Profile Built | 2026-06-25 23:34:36 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.