# IP Intelligence Briefing: 13.38.39.20/32
Classification: Low Risk / Legitimate Infrastructure
Date of Analysis: 2026-08-13
## Executive Summary
IP address 13.38.39.20 resolves to Amazon Web Services infrastructure in France and presents no threat indicators. The address is classified as clean with a risk score of 0. No defensive action is recommended at this time.
## Ownership and Geolocation
- Organization: Amazon Data Services France
- ASN: 16509 (AMAZON-CDG)
- CIDR Block: 13.36.0.0/14
- Location: Paris, Île-de-France, France (48.86°N, 2.35°E)
- DNS Hostname: ec2-13-38-39-20.eu-west-3.compute.amazonaws.com
The IP address is part of AWS's European cloud infrastructure network registered with ARIN. DNS resolution confirms forward and reverse consistency.
## Threat Assessment
Risk Score: 0 (Low Risk)
Abuse Confidence Score: Not applicable
Blacklist Status: Clean (0 blacklist entries)
Campaign Associations: None detected
Threat indicators analysis returned no matches. The IP is not flagged as a known attacker, spam source, or Tor exit node. No malicious campaigns were correlated with this address.
## Network Activity and Services
- Open Ports: None detected
- TLS Certificate: Not present
- HTTP Services: Not responding
- Network Role: Firewalled / No Services
No active services were observed on the IP, which is consistent with cloud infrastructure that may be configured for specific internal workloads or terminated at the edge.
## Historical Analysis
Sixteen observations were recorded for this address. Key findings:
- Ownership Stability: No ownership changes detected
- Threat Persistence: 0 days (no persistent malicious activity)
- Malicious Classification: Not persistently malicious
- Recent Activity: Most recent signals observed on 2026-08-13
The IP has maintained a stable ownership profile with no escalation in threat signals over the observation period.
## Neighborhood Analysis
Subnet 13.38.39.20/24 analysis:
- Total Neighbors: 0
- Abuse Density: 0 (clean)
- Threat Siblings: 0
- Classification: Clean
The immediate /24 subnet shows no neighboring addresses with threat indicators, suggesting this is an isolated infrastructure assignment within AWS's broader cloud network.
## Relationships
Three entity relationships were identified:
1. DNS Association: ec2-13-38-39-20.eu-west-3.compute.amazonaws.com
2. Same Network: AMAZON-CDG network
3. DNS Association: ec2-13-38-39-20.eu-west-3.compute.amazonaws.com (duplicate entry)
All relationships point to legitimate AWS infrastructure rather than adversarial connections.
## Recommended Actions
No firewall rules or blocking recommendations are warranted. The IP address:
- Has a risk score of 0
- Is associated with legitimate cloud infrastructure
- Shows no threat indicators
- Is clean within its subnet
SOC Analyst Recommendation: Monitor passively as part of normal network traffic. No blocking, rate-limiting, or investigative actions are required at this time.
---
*Report generated by IPDebrief intelligence platform. All data points sourced from automated network observations and public threat intelligence feeds.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Amazon Data Services France |
| ASN | AS16509 |
| Network Name | AMAZON-CDG |
| CIDR Block | 13.36.0.0/14 |
| RIR | ARIN |
| Country | France |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ec2-13-38-39-20.eu-west-3.compute.amazonaws.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ec2-13-38-39-20.eu-west-3.compute.amazonaws.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | 1/2 domains |
| DMARC | 1/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 22% | 6 | 6 |
| Data Coherence | Mixed Signals (68%) โ 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ TLS certificate claims US but primary geo says FR
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-08 16:30:02 UTC |
| Last Seen | 2026-08-30 15:58:58 UTC |
| Profile Built | 2026-08-29 04:30:00 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 26 |
Full dossier details are available via our API.