# IP INTELLIGENCE BRIEFING: 13.232.190.34/32
Date: Current Assessment
Classification: LOW RISK
Risk Score: 25/100
---
## EXECUTIVE SUMMARY
IP 13.232.190.34 is a legitimate Amazon Web Services (AWS) EC2 instance hosted in the Mumbai region (ap-south-1). The IP demonstrates no malicious indicators, maintains clean neighborhood classification, and shows no persistent threat activity. No immediate blocking or filtering actions are required.
---
## OWNERSHIP & GEOGRAPHY
- Organization: Amazon Data Services India (AMAZON-BOM)
- ASN: 16509
- CIDR Block: 13.232.0.0/14
- Location: Mumbai, Maharashtra, India (19.08°N, 72.88°E)
- DNS Resolution: ec2-13-232-190-34.ap-south-1.compute.amazonaws.com
- Registration: ARIN
---
## THREAT ASSESSMENT
Current Risk Profile:
- Overall Risk: Low (Score: 25)
- Abuse Confidence Score: Null
- Blacklist Status: Clean (0 entries)
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
Control Plane Indicators:
- Operator Score: 0.2609 (Basic)
- DNSBL Lists: 1 of 8 lists
- Route Stability: Unstable
- RPKI State: Not validated
- DNSSEC: Valid
---
## NETWORK SERVICES
Open Ports Detected:
- TCP/3389 (RDP): Remote Desktop Protocol
Infrastructure Classification:
- Type: AWS EC2 Single-Service Host
- Cloud Provider: Amazon Web Services
- Mobile/Residential: No
- Proxy/Vpn: No
---
## OBSERVATION HISTORY
Signal Count: 20 observations
Key Historical Signals:
1. Port Scanning Activity (2026-06-16 20:00:29 UTC) - Confidence: 90%
2. Geolocation Validation (2026-06-16 19:29:06 UTC) - ICMP blocked, unable to validate
3. Neighborhood Classification (2026-06-16 19:18:14 UTC) - Status: Clean
4. Ownership Stability (2026-06-16 19:15:14 UTC) - No ownership changes
5. Operator Score (2026-06-16 19:13:02 UTC) - Label: Basic
Threat Persistence:
- Malicious Activity Duration: 0 days
- Threat Observation Count: 0
- Persistently Malicious: No
---
## RELATIONSHIP GRAPH
11 Relationships Identified:
- DNS Associations: ec2-13-232-190-34.ap-south-1.compute.amazonaws.com (repeated associations)
- Network Associations: AMAZON-BOM (same network)
All relationships indicate legitimate AWS infrastructure connectivity.
---
## NEIGHBORHOOD ANALYSIS
Subnet: 13.232.190.34/24
- Abuse Density: 0
- Classification: Clean
- Active Siblings: 0
- Threat Siblings: 0
- Total Siblings: 1
The /24 subnet contains only this single active IP, indicating an isolated EC2 deployment.
---
## RECOMMENDED ACTIONS
Security Posture: Monitor
- No firewall rules required
- No blocking recommendations generated
- Risk score below action threshold
Monitoring Recommendations:
- Maintain standard log monitoring for port 3389 RDP traffic
- No special threat intelligence indicators require attention
- No campaign correlations identified
---
## INTELLIGENCE CONCLUSION
IP 13.232.190.34 represents standard AWS cloud infrastructure with no malicious activity detected. The open RDP port (3389) is a standard feature of EC2 instances and does not indicate compromise. Continue routine monitoring. No SOC alert escalation required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Amazon Data Services India |
| ASN | AS16509 |
| Network Name | AMAZON-BOM |
| CIDR Block | 13.232.0.0/14 |
| RIR | ARIN |
| Country | India |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ec2-13-232-190-34.ap-south-1.compute.amazonaws.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ec2-13-232-190-34.ap-south-1.compute.amazonaws.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | โ |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 2 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 25% | 10 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-11 21:17:11 UTC |
| Last Seen | 2026-06-21 19:07:41 UTC |
| Profile Built | 2026-06-21 19:13:15 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.