Intelligence Briefing: IP Address 107.23.73.16/32
Summary:
The IP address 107.23.73.16/32 was analyzed using multiple tools to gather comprehensive intelligence. The analysis focused on understanding the behavior, relationships, and neighborhood context of this IP address. The following is a detailed summary of the findings:
Observation History:
- Activity Patterns: The IP address exhibited consistent activity patterns, primarily associated with outgoing traffic to various external domains. The traffic was predominantly HTTP/HTTPS, suggesting web-based interactions.
- Geolocation: The IP is geolocated to the United States. This information is consistent with the general location of its registered organization.
- Domain Associations: The IP address was linked to several domains, many of which are associated with legitimate business operations. However, a subset of these domains had been flagged for hosting content related to adware.
Relationships:
- Organizational Ties: The IP address is registered under a well-known technology company based in the United States. This organization has a history of providing cloud services and web hosting.
- Network Connections: Connections from this IP to other IPs within the same organization were observed, indicating internal network activity. Additionally, there were connections to third-party service providers, likely for cloud-based services.
Neighborhood Data:
- Subnet Analysis: The subnet analysis revealed that 107.23.73.16 is part of a larger block allocated to the same organization. Other IPs within this subnet were associated with similar web services and cloud infrastructure.
- Peer IPs: Several peer IPs within the same subnet were observed engaging in similar outbound traffic patterns. Some of these peer IPs were linked to domains with low reputation scores, raising potential concerns about adware or other unwanted software.
Threat Assessment:
- Risk Level: Moderate. While the majority of the observed activity is consistent with legitimate business operations, the presence of domains associated with adware suggests a potential risk of unwanted software distribution.
- Actionable Recommendations:
- Monitor outbound traffic from this IP for anomalies, particularly towards domains with low reputation scores.
- Implement web filtering to block traffic to known adware-hosting domains.
- Conduct regular scans for adware on systems communicating with this IP.
Conclusion:
The IP address 107.23.73.16/32 is primarily associated with legitimate business operations under a well-known technology company. However, the presence of adware-related domains in its activity profile warrants monitoring and precautionary measures to mitigate potential security risks.
This intelligence briefing provides a clear understanding of the IP's behavior and associated risks, enabling SOC analysts to take informed actions to protect their network environments.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon.com, Inc. |
| ASN | AS14618 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-107-23-73-16.compute-1.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-107-23-73-16.compute-1.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-23 00:17:38 UTC |
| Last Seen | 2026-06-28 20:08:09 UTC |
| Profile Built | 2026-06-29 08:11:56 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.