IP Intelligence Briefing: 13.200.209.159
Date: 2026-06-07
---
**1. Core Profile**
- Risk Score: 25 (Low Risk)
- Ownership: Amazon Data Services India (ASN 16509)
- Geolocation: Mumbai, Maharashtra, India (19.08°N, 72.88°E)
- Network Role: AWS Cloud Compute Instance (Firewalled, No Open Services)
- Threat Indicators: No malicious activity detected (no C2, malware, or abuse indicators).
---
**2. Observation History**
- Recent Activity (2026-06-07):
- Confirmed as AWS cloud infrastructure (no residential/mobile/VPN/CDN).
- Geolocation validated via DNS (Mumbai, India) with ICMP blocking.
- No active network scans or open ports detected.
- Historical Trends:
- No persistent malicious behavior (threat persistence days: 0).
- Single observation of DNS resolution to `ec2-13-200-209-159.ap-south-1.compute.amazonaws.com`.
---
**3. Network Relationships**
- DNS Associations:
- Linked to AWS EC2 instance `ec2-13-200-209-159.ap-south-1.compute.amazonaws.com`.
- Subnet Affiliation:
- Part of AWS network `AMAZON-BOM` (AS16509).
- No External Threat Links:
- No connections to known malicious domains, organizations, or certificates.
---
**4. Neighborhood Analysis**
- Subnet: 13.200.209.159/24
- Neighbor Activity:
- No neighboring IPs detected (likely private or non-routable subnet).
- Abuse Density: 0% (clean subnet).
---
**5. Recommendations**
- Monitoring:
- Track AWS cloud instance logs for unexpected activity.
- Ensure security groups/firewalls restrict access to legitimate services.
- No Action Required:
- No malicious indicators or network threats detected.
---
Conclusion: 13.200.209.159 is a legitimate AWS cloud compute instance with no evidence of malicious activity. Monitor for configuration drift or unauthorized access.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Amazon Data Services India |
| ASN | AS16509 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ec2-13-200-209-159.ap-south-1.compute.amazonaws.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ec2-13-200-209-159.ap-south-1.compute.amazonaws.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 22% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-14 01:08:27 UTC |
| Last Seen | 2026-06-28 00:00:56 UTC |
| Profile Built | 2026-06-28 18:04:52 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.