IP 100.20.249.207/32 was assessed as Low Risk with a risk score of 25. Ownership traces to Amazon.com, Inc. (ASN: 16509), specifically an EC2 instance within the us-west-2 region (Boardman, OR). The network role was classified as a Web Server.
Active services included HTTPS on port 443. DNS reverse resolution confirmed the hostname ec2-100-20-249-207.us-west-2.compute.amazonaws.com. TLS certificates were issued by Sectigo for the domain samsungcloud.com.
Threat analysis indicated no known campaigns, zero active attacker classifications, and zero honeypot hits. The profile was tagged as a Suspicious Host with one DNSBL listing out of eight total lists.
Data contradictions were observed regarding geolocation and certificate subject country, which conflicted between US and KR. Due to these signal contradictions, monitoring was recommended with low severity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon.com, Inc. |
| ASN | AS16509 |
| Network Name | AMAZO-ZPDX |
| CIDR Block | 100.20.0.0/14 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-100-20-249-207.us-west-2.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-100-20-249-207.us-west-2.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | *.samsungcloud.comsamsungcloud.com |
| Valid From | 2026-09-07T00:00:00+00:00 |
| Valid Until | 2027-03-24T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 198 days |
| Serial Number | 7AFA9F14AE3DDA1FB02ADB5E78837276 |
| Thumbprint | AF00399B14B8835A96E0387655E1630BD2668B21 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 42% | 2 | 4 |
| routing | 20% | 1 | 1 |
| services | 40% | 2 | 3 |
| ownership | 40% | 2 | 3 |
| reputation | 34% | 1 | 3 |
| geolocation | 40% | 2 | 3 |
| Overall | 36% | 10 | 17 |
| Data Coherence | Mixed Signals (68%) β 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
β TLS certificate claims KR but primary geo says US
π Observation Timeline π Live
| First Seen | 2026-09-20 11:10:25 UTC |
| Last Seen | 2026-09-23 06:52:34 UTC |
| Profile Built | 2026-09-23 11:24:43 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 36 |
Full dossier details are available via our API.