# IP Intelligence Briefing: 100.54.149.28/32
## Executive Summary
IP address 100.54.149.28 is identified as a low-risk (score: 25/100) Amazon Web Services EC2 instance located in Ashburn, Virginia. The asset demonstrates clean network characteristics with no active threat indicators and is classified as benign cloud infrastructure.
## Asset Profile
- Risk Score: 25/100 (Low Risk)
- Provider: Amazon Web Services (ASN: 14618)
- Organization: Amazon Data Services Northern Virginia
- Geolocation: Ashburn, VA, United States (39.04°N, 77.49°W)
- Infrastructure Type: CloudCompute / Web Server
- Network Classification: Cloud-hosted infrastructure within AWS IAD region
## Technical Indicators
- Open Ports: 80/TCP (HTTP), 443/TCP (HTTPS), 22/TCP (SSH)
- Server Software: nginx/1.24.0 (Ubuntu)
- TLS Certificate: Issued by Let's Encrypt for domain "ecommerce-playground.testmu.in"
- DNS PTR Record: ec2-100-54-149-28.compute-1.amazonaws.com
- DNSBL Status: Listed on 1 of 8 DNSBL feeds (dnsblListedCount: 1)
- Forward DNS Resolution: Confirmed to amazonaws.com domain
## Threat Intelligence Assessment
- Known Threats: None detected
- Campaign Correlation: No matches (0 cert matches, 0 correlated IPs)
- Abuse Confidence: Not applicable (low-risk asset)
- Tor Exit Node: False
- Known Attacker: False
- Spam Source: False
- Blacklist Count: 0
## Historical Observations
Analysis of 22 historical signals indicates stable operation with no escalation of risk behavior:
- Recent DNS resolution alternates between testmu.in and amazonaws.com domains
- Connection failures observed on June 20, 2026 (confidence: 30%)
- Geographic attribution consistently identifies Ashburn, VA region
- No persistent malicious activity detected over observation period
- Ownership stability: 0 changes recorded
## Network Neighborhood
The /24 subnet (100.54.149.28/24) demonstrates clean characteristics:
- Abuse Density: 0%
- Classification: Clean
- Active Siblings: 1 (the target IP only)
- Threat Siblings: 0
## Relationship Graph
Forty-nine relationships were identified, primarily consisting of:
- DNS associations to AWS compute hostnames (ec2-100-54-149-28.compute-1.amazonaws.com)
- Network associations within AMAZON-IAD region
- No external threat actor correlations
## Recommended Actions
Based on current risk profile, no immediate defensive actions are required. The IP represents legitimate cloud infrastructure with standard web hosting services. Recommended approach:
1. Allow through perimeter firewall (standard AWS EC2 traffic profile)
2. Monitor for any changes in DNS resolution patterns or service changes
3. No blocking recommended at this time
## Risk Assessment Conclusion
This IP address represents benign cloud infrastructure hosting a test/development domain. The low risk score, clean neighborhood, absence of threat indicators, and standard AWS hosting profile indicate no immediate security concern. SOC analysts may permit traffic with standard logging and monitoring practices.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services Northern Virginia |
| ASN | AS14618 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-100-54-149-28.compute-1.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-100-54-149-28.compute-1.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | 1/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | ecommerce-playground.testmu.in |
| Valid From | 2026-04-08T08:07:14+00:00 |
| Valid Until | 2026-07-07T08:07:13+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 0528E33DEBE7169A95894B7BBB0CA676C997 |
| Thumbprint | 79ED0AF0327030CC6918C5384134636F8B4952B6 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 26% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 18% | 1 | 2 |
| geolocation | 39% | 2 | 3 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-23 00:17:26 UTC |
| Last Seen | 2026-06-28 20:07:53 UTC |
| Profile Built | 2026-06-29 08:11:56 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.