# INTELLIGENCE BRIEFING: IP 108.129.147.25/32
Classification: LOW RISK
Date: Current
Analysis ID: IP-108.129.147.25-001
---
## EXECUTIVE SUMMARY
Intellect analysis of IP address 108.129.147.25/32 classifies the address as LOW RISK with an overall risk score of 25. The IP is an AWS EC2 instance deployed in Dublin, Ireland (eu-west-1 region), operating as a Splunk infrastructure endpoint. No active threat indicators or malicious activity patterns were detected during this assessment.
---
## OWNERSHIP & INFRASTRUCTURE
| Attribute | Value |
|---|---|
| **ASN** | 16509 (Amazon.com, Inc.) |
| **Organization** | Amazon Data Services Ireland Limited |
| **Network** | AMAZON-DUB |
| **Location** | Dublin, Ireland (53.35°N, -6.26°W) |
| **CIDR Block** | 108.128.0.0/13 (BGP Prefix) |
| **RIR** | ARIN |
| **Infrastructure Type** | CloudCompute |
The IP is hosted on Amazon Web Services infrastructure, specifically within the Ireland EU-West-1 region. The address is properly registered and maintains route stability with no recent route changes observed.
---
## NETWORK SERVICES & FINGERPRINTING
| Service | Port | Protocol | Details |
|---|---|---|---|
| HTTPS | 443 | TCP | Web service endpoint |
| SSH | 22 | TCP | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
DNS Resolution:
- PTR Record: `ec2-108-129-147-25.eu-west-1.compute.amazonaws.com`
- Forward Confirmation: Valid
- Hosted Domain: `amazonaws.com`
TLS Certificate:
- Issuer: Let's Encrypt (R13)
- Subject: `*.students.splunk.education`
- Algorithm: Valid Let's Encrypt certificate
Server Fingerprint: Splunkd (HTTP 303 response)
---
## THREAT INTELLIGENCE
| Indicator | Status |
|---|---|
| Known Attacker | No |
| Spam Source | No |
| Tor Exit Node | No |
| Blacklist Count | 0 |
| Abused Confidence Score | Not applicable |
| Known Campaigns | None |
| DNSBL Listed | 1 (of 8 total lists) |
| Threat Persistence | 0 days |
Threat Observation Count: 1 (historical, non-persistent)
No active threat indicators were identified during this assessment. The IP is not associated with known malicious campaigns or threat actor infrastructure.
---
## NEIGHBORHOOD ANALYSIS
Subnet: 108.129.147.25/24
| Metric | Value |
|---|---|
| Abuse Density | 0 (Low) |
| Classification | Mostly Clean |
| Total Siblings | 1 |
| Active Siblings | 0 |
| Threat Siblings | 1 |
| Inherited Risk | 2 |
The surrounding /24 subnet demonstrates minimal abuse activity. One threat sibling IP was observed in historical data, but no active threats were detected in the immediate neighborhood.
---
## OBSERVATION HISTORY
Total Observations: 27 signals collected over monitoring period
Recent Activity:
- 2026-06-28: Routing and reputation signals observed (confidence: 0.25-0.60)
- 2026-06-20: HTTP/HTTPS service fingerprinting completed (confidence: 0.80-0.90)
The IP's temporal profile shows consistent low-risk characteristics throughout the observation window. No escalating threat patterns were identified.
---
## RELATIONSHIP MAPPING
Total Relationships: 38
Key Associations:
- DNS: `ec2-108-129-147-25.eu-west-1.compute.amazonaws.com`
- Network: AMAZON-DUB (AWS Dublin region)
- Multiple DNS hostname associations to same EC2 endpoint
No suspicious external relationships were identified. The IP maintains typical AWS infrastructure relationship patterns.
---
## RECOMMENDED ACTIONS
Firewall/Security Recommendations:
- No action required โ Risk score (25) indicates minimal threat
- Standard AWS infrastructure security policies apply
- Monitor for any behavioral changes if legitimate traffic patterns deviate
SOC Analyst Notes:
- This is legitimate AWS infrastructure, not a malicious IP
- TLS certificate indicates educational Splunk deployment
- Standard cloud infrastructure with no anomalous activity
---
## CONCLUSION
IP address 108.129.147.25/32 is a legitimate AWS EC2 instance deployed in Dublin, Ireland, operating as part of Splunk educational infrastructure. The address demonstrates low-risk characteristics with no active threat indicators. No defensive action is required at this time.
Status: MONITOR (LOW RISK)
Priority: LOW
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Amazon Data Services Ireland Limited |
| ASN | AS16509 |
| Network Name | โ |
| CIDR Block | 108.128.0.0/13 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ec2-108-129-147-25.eu-west-1.compute.amazonaws.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ec2-108-129-147-25.eu-west-1.compute.amazonaws.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | 1/2 domains |
| DMARC | 1/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Splunkd |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
๐ TLS Certificate
| SANs | *.students.splunk.education |
| Valid From | 2026-04-13T23:22:38+00:00 |
| Valid Until | 2026-07-12T23:22:37+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 05A9315DAC547E0906584DD67282E8BAAE59 |
| Thumbprint | 0919B45E6B9ACC1CE057466F165AE7D6A1690727 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 24% | 2 | 3 |
| services | 30% | 2 | 3 |
| ownership | 27% | 3 | 4 |
| reputation | 32% | 1 | 3 |
| geolocation | 26% | 2 | 2 |
| Overall | 29% | 12 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-23 18:28:01 UTC |
| Last Seen | 2026-06-28 22:12:13 UTC |
| Profile Built | 2026-06-29 04:14:36 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 28 |
Full dossier details are available via our API.