# IP Intelligence Briefing: 9.138.14.56/32
Classification: LOW RISK - ISP Residential/Business
Analysis Date: 2026-06-25
---
## Executive Summary
IP 9.138.14.56 is assigned to Brightspeed (ASN 19901) and is classified as low risk. The address shows no active threat indicators, no open services, and minimal reputation risk. While listed on one DNSBL feed, the IP demonstrates stable infrastructure characteristics consistent with residential/business broadband access. No immediate defensive action recommended; continue routine monitoring.
---
## Threat Profile
Risk Score: 25/100 (Low Risk)
Reputation: Low Risk
Abuse Confidence: Not elevated
Threat Indicators: None detected
Classification Flags:
- No open ports/services detected
- Not a Tor exit node
- Not a known attacker
- Not a spam source
- Not hosted/proxy/VPN infrastructure
- Not bogon or anycast
---
## Ownership & Geolocation
Organization: Brightspeed
ASN: 19901
Country: United States (US)
Region: North Carolina
City: Rocky Mount
Network Block: 9.138.12.0/22 (BRIGHTSPEED-BLOCK11)
Registration: ARIN
DNS Resolution: dhcp-9-138-14-56.gobrightspeed.net (typical ISP DHCP hostname)
PTR Record: Forward confirmed
---
## Neighborhood Assessment
Subnet: 9.138.14.56/24
Abuse Density: 0 (Clean)
Threat Siblings: 0
Active Siblings: 0
Total Siblings: 1
The /24 subnet demonstrates no abuse activity and inherits a clean classification.
---
## Relationship Graph
Key Associations (36 total):
- Network: BRIGHTSPEED-BLOCK11
- DNS Hostname: dhcp-9-138-14-56.gobrightspeed.net
- Infrastructure: Standard ISP residential/business block
No anomalous relationships to external malicious entities observed.
---
## Observation History
Total Signals: 22 observations
Recent Activity: Stable with low-confidence signals (0.19-0.85)
Notable Historical Events:
- DNSBL listing detected (signal_type_id: 2344) - 1 of 8 lists, high severity
- Geolocation data: US, 39.83°N, -98.58°W (2500km accuracy)
- Operator score: 0.2609 (Basic classification)
- Route stability: False
---
## Recommended Security Actions
Current Risk Level: Minimal
Action: Monitor only - No blocking recommended
Firewall Rules: None required
WAF Rules: None required
Rationale: Risk score of 25 falls below threshold for automated blocking. The IP exhibits characteristics of legitimate broadband access with no active exploit patterns or command-and-control associations.
---
## Intelligence Assessment
IP 9.138.14.56 demonstrates characteristics consistent with normal ISP-assigned residential or small business broadband infrastructure. The absence of open services, clean neighborhood classification, and lack of threat indicators support continued routine monitoring rather than defensive intervention. The single DNSBL listing warrants periodic review but does not warrant immediate action.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Brightspeed |
| ASN | AS19901 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | dhcp-9-138-14-56.gobrightspeed.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | dhcp-9-138-14-56.gobrightspeed.net |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 19% | 2 | 2 |
| Overall | 18% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-09 22:11:34 UTC |
| Last Seen | 2026-06-25 21:47:55 UTC |
| Profile Built | 2026-06-25 21:54:38 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.