IPDebrief

73.153.3.78

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

## IPDEBRIEF INTELLIGENCE BRIEFING

Target IP: 73.153.3.78/32

Classification: High-Risk Residential Cable

Report Date: 2026-06-23

---

EXECUTIVE SUMMARY

IP address 73.153.3.78 is classified as High Risk (risk score: 70/100) and is associated with Comcast Cable Communications, LLC (ASN 7922). The IP is geolocated to Denver, Colorado, USA, operating as a residential cable connection. The IP is currently listed on 3 DNS blacklists out of 8 total listings with high-severity classifications observed in recent activity.

---

OWNERSHIP & NETWORK CLASSIFICATION

AttributeValue
**ASN**7922 (Comcast Cable Communications, LLC)
**Organization**Comcast Cable Communications, LLC
**Network Type**Residential Cable
**Geolocation**Denver, CO, US (2500km accuracy radius)
**DNS PTR**c-73-153-3-78.hsd1.co.comcast.net
**Forward Resolution**Confirmed (1 hostname)

---

THREAT INTELLIGENCE

Current Status:

Recent Activity (Signal History - 21 observations):

---

NEIGHBORHOOD ANALYSIS

Subnet: 73.153.3.78/24

Abuse Density: 1.0 (Maximum)

Classification: mostly_clean (subnet-level)

Total Siblings: 2

Threat Siblings: 1

High-Risk Neighbor Detected:

The /24 subnet exhibits elevated abuse density with one additional high-risk IP address.

---

SERVICE FINGERPRINT

ServicePortProtocolStatus
SSH22TCPOpen
**Banner**--SSH-2.0-OpenSSH_8.1

No HTTP/web services or TLS certificates detected.

---

RELATIONSHIP GRAPH

Key Associations:

---

RECOMMENDED ACTIONS

Immediate:

1. Increase logging verbosity and review recent activity from this IP address

2. Block traffic from 73.153.3.78/32 at perimeter firewall

Firewall Implementation Rules:

iptables:

```bash

iptables -A INPUT -s 73.153.3.78 -j DROP

```

nftables:

```bash

nft add rule inet filter input ip saddr 73.153.3.78 drop

```

Cloudflare WAF:

```json

{

"description": "Block 73.153.3.78 β€” IPDebrief risk score 70",

"action": "block",

"filter": {"expression": "ip.src eq 73.153.3.78"}

}

```

AWS WAF:

```json

{

"Addresses": ["73.153.3.78/32"],

"Description": "IPDebrief risk 70"

}

```

---

ANALYST NOTES

This IP address represents a Comcast residential cable connection with an elevated risk profile. The combination of high DNSBL listings, high abuse density in the /24 subnet, and a high-risk neighbor (73.153.3.166, score 80) suggests potential malicious activity or compromised endpoint behavior.

Recommendation: Block at perimeter firewall and monitor for additional related activity from the 73.153.3.0/24 subnet. Consider correlation with other indicators from the neighboring IP 73.153.3.166 for broader threat assessment.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionCO
CityDenver
Timezoneβ€”
Latitude39.87
Longitude-104.92

🏒 Ownership & Registration

OrganizationComcast Cable Communications, LLC
ASNAS7922
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRc-73-153-3-78.hsd1.co.comcast.net
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesc-73-153-3-78.hsd1.co.comcast.net

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureResidential
Service PurposeSingle-Service Host
Network TierEnd-User β€” Residential ISP endpoint
Residential

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_8.1
⚠ Unusual for residential β€” open services on a home connection may indicate self-hosting, compromise, or misconfigured networking equipment.

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
37%
23
routing
8%
11
services
15%
22
ownership
27%
23
reputation
15%
12
geolocation
21%
22
Overall21%1013
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-07 23:04:34 UTC
Last Seen2026-06-26 18:11:33 UTC
Profile Built2026-06-26 18:20:59 UTC
Data FreshnessLive
Signal Types20
Total Observations20
πŸ” 20 signal types Β· 20 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.