IPDebrief

107.20.255.194

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 107.20.255.194

## Executive Summary

The IP address 107.20.255.194 presents a Low Risk profile (Score: 25/100) associated with Amazon Web Services infrastructure. The address is operational but currently firewalled with no active services detected. No malicious threat indicators, campaign associations, or blacklisting patterns were observed across multiple data sources.

---

## Ownership and Infrastructure Classification

AttributeValue
**Organization**Amazon.com, Inc.
**Network**AMAZON-EC2-8
**CIDR Block**107.20.0.0/14
**ASN**14618
**Location**Ashburn, VA, US
**Infrastructure Type**Cloud (AWS EC2)
**Service Status**Firewalled / No Services

The IP belongs to Amazon's EC2 infrastructure block. DNS resolution indicates association with Amazon's crawl services (107-20-255-194.crawl.amazonbot.amazon), suggesting this address hosts web crawling or bot infrastructure.

---

## Risk Assessment

Current Risk Metrics

Network Role Analysis

---

## Threat Intelligence Findings

Active Threat Indicators

DNS Reputation

---

## Neighborhood Analysis (107.20.255.0/24)

MetricValue
**Abuse Density**0 (Clean)
**Total Siblings**1
**Active Siblings**1
**Threat Siblings**0
**Classification**Clean
**High/Medium Risk Neighbors**0

The /24 subnet shows zero abuse density with no threat-adjacent IPs detected. This indicates the address operates in a low-risk network environment.

---

## Observation History

Total Observations: 21 signals recorded

Recent Activity Timeline

Risk Trend

No escalation in threat signals observed. The IP maintains consistent low-risk classification across all observation windows.

---

## Relationship Graph

Connected Entities

All relationships indicate legitimate AWS infrastructure associations with no external threat actor connections.

---

## Recommended Security Actions

Current Recommendations

Rationale

The IP presents a low-risk profile with legitimate cloud infrastructure characteristics. No immediate security actions are warranted. The address is associated with Amazon's crawl services and shows no malicious behavior patterns.

---

## Conclusion

IP 107.20.255.194 is classified as Low Risk AWS infrastructure used for Amazon's crawl/bot operations. The address exhibits no malicious indicators, operates within a clean subnet environment, and shows consistent benign behavior across observation periods. SOC analysts may treat this as legitimate infrastructure with no immediate threat to the network.

Recommended Action: Monitor with standard traffic logging; no blocking required.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionVA
CityAshburn
TimezoneAmerica/New_York
Latitude39.04
Longitude-77.49

🏒 Ownership & Registration

OrganizationAmazon.com, Inc.
ASNAS16509
Network NameAMAZON-EC2-8
CIDR Block107.20.0.0/14
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR107-20-255-194.crawl.amazonbot.amazon
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnames107-20-255-194.crawl.amazonbot.amazon

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 β€” Basic operator with some routing infrastructure
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
42%
25
routing
13%
11
services
19%
22
ownership
30%
23
reputation
28%
13
geolocation
33%
24
Overall27%1018
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-08-02 06:46:23 UTC
Last Seen2026-08-13 03:33:44 UTC
Profile Built2026-08-13 04:08:28 UTC
Data FreshnessLive
Signal Types23
Total Observations25
πŸ” 23 signal types Β· 25 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.