IPDebrief

9.138.14.56

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 9.138.14.56/32

Classification: LOW RISK - ISP Residential/Business

Analysis Date: 2026-06-25

---

## Executive Summary

IP 9.138.14.56 is assigned to Brightspeed (ASN 19901) and is classified as low risk. The address shows no active threat indicators, no open services, and minimal reputation risk. While listed on one DNSBL feed, the IP demonstrates stable infrastructure characteristics consistent with residential/business broadband access. No immediate defensive action recommended; continue routine monitoring.

---

## Threat Profile

Risk Score: 25/100 (Low Risk)

Reputation: Low Risk

Abuse Confidence: Not elevated

Threat Indicators: None detected

Classification Flags:

---

## Ownership & Geolocation

Organization: Brightspeed

ASN: 19901

Country: United States (US)

Region: North Carolina

City: Rocky Mount

Network Block: 9.138.12.0/22 (BRIGHTSPEED-BLOCK11)

Registration: ARIN

DNS Resolution: dhcp-9-138-14-56.gobrightspeed.net (typical ISP DHCP hostname)

PTR Record: Forward confirmed

---

## Neighborhood Assessment

Subnet: 9.138.14.56/24

Abuse Density: 0 (Clean)

Threat Siblings: 0

Active Siblings: 0

Total Siblings: 1

The /24 subnet demonstrates no abuse activity and inherits a clean classification.

---

## Relationship Graph

Key Associations (36 total):

No anomalous relationships to external malicious entities observed.

---

## Observation History

Total Signals: 22 observations

Recent Activity: Stable with low-confidence signals (0.19-0.85)

Notable Historical Events:

---

## Recommended Security Actions

Current Risk Level: Minimal

Action: Monitor only - No blocking recommended

Firewall Rules: None required

WAF Rules: None required

Rationale: Risk score of 25 falls below threshold for automated blocking. The IP exhibits characteristics of legitimate broadband access with no active exploit patterns or command-and-control associations.

---

## Intelligence Assessment

IP 9.138.14.56 demonstrates characteristics consistent with normal ISP-assigned residential or small business broadband infrastructure. The absence of open services, clean neighborhood classification, and lack of threat indicators support continued routine monitoring rather than defensive intervention. The single DNSBL listing warrants periodic review but does not warrant immediate action.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionNC
CityRocky Mount
Timezoneβ€”
Latitude35.94
Longitude-77.76

🏒 Ownership & Registration

OrganizationBrightspeed
ASNAS19901
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRdhcp-9-138-14-56.gobrightspeed.net
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesdhcp-9-138-14-56.gobrightspeed.net

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown β€” Insufficient routing data to classify
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
33%
24
routing
8%
11
services
15%
22
ownership
20%
23
reputation
13%
12
geolocation
19%
22
Overall18%1014
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-09 22:11:34 UTC
Last Seen2026-06-25 21:47:55 UTC
Profile Built2026-06-25 21:54:38 UTC
Data FreshnessLive
Signal Types20
Total Observations20
πŸ” 20 signal types Β· 20 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.