Intelligence Briefing: 96.216.134.10/32
Overview
The IP address was classified as a Low Risk endpoint with a risk score of 25. Network role identification confirmed it as a Residential Endpoint operating within the Comcast Cable Communications, LLC infrastructure (ASN 7922). The associated CIDR block was 96.216.0.0/14.
Threat Assessment
The host was categorized as a Suspicious Host with a "suspicious" tag. No specific threat indicators, known campaigns, or blacklist entries were recorded, and the blacklisting count remained at zero. No active attacker status was confirmed.
Geolocation and Validation
Geolocation data was attributed to New York, US. However, validation checks flagged a contradiction between the claimed location and RTT physics measurements. Analysis indicated a distance of 7625.7km against an RTT of 36ms, resulting in a false GeoPlausible status.
Network Behavior
Service scans did not identify any open ports. Behavioral analysis showed zero honeypot hits, enumeration strikes, or WAF violations. DNS hygiene was rated as Good with SPF and DMARC records present.
Recommendation
The analysis recommended a Monitor action with Low severity. This recommendation was driven by the presence of signal contradictions regarding geolocation and RTT consistency, necessitating observation for potential changes.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Comcast Cable Communications, LLC |
| ASN | AS7922 |
| Network Name | COMCAST-E1-19 |
| CIDR Block | 96.216.0.0/14 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | β |
π DNS Intelligence
| PTR | ae-501-ar01.pontiac.mi.michigan.comcast.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ae-501-ar01.pontiac.mi.michigan.comcast.net |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User β Residential ISP endpoint |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 37% | 2 | 6 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 32% | 1 | 5 |
| geolocation | 27% | 2 | 3 |
| Overall | 24% | 10 | 19 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-29 09:59:35 UTC |
| Last Seen | 2026-09-20 06:04:54 UTC |
| Profile Built | 2026-09-23 01:36:27 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 33 |
Full dossier details are available via our API.