# IP Intelligence Briefing: 13.49.141.132
## Executive Summary
IP address 13.49.141.132 is a cloud compute instance belonging to Amazon Web Services (AWS) operating within the eu-north-1 region (Stockholm, Sweden). The IP carries a Moderate Risk rating (score: 50) and is associated with legitimate cloud infrastructure while showing some blacklist presence. No active threat campaigns or malicious activity indicators were detected.
## Ownership & Infrastructure Profile
- Organization: Amazon Data Services Sweden
- ASN: 16509 (AMAZON-02)
- CIDR Block: 13.48.0.0/14
- Geolocation: Stockholm, Sweden (59.33°N, 18.07°E)
- Infrastructure Type: CloudCompute (EC2 instance)
- Hostname: ec2-13-49-141-132.eu-north-1.compute.amazonaws.com
## Technical Observations
- Active Services: SSH (22/tcp) with OpenSSH 8.0 banner
- DNS Resolution: Forward confirmed to Amazon compute hostname
- Email Authentication: SPF and DMARC records present
- Control Plane: Route stability flagged as unstable; 2 DNSBL listings across 8 total lists
## Risk Assessment
- Overall Risk Score: 50 (Moderate)
- Operator Score: 0.2609 (Basic classification)
- Abuse Density: 1 (low)
- DNSBL Status: Listed on 2 threat feeds
## Temporal Analysis
Signal observation history (25 observations) indicates intermittent blacklist activity. Notable observations include:
- June 17-18, 2026: Multiple blacklist listings with high severity ratings
- ASN geolocation resolution showed US origin in some feed lookups despite Swedish hosting
- No evidence of persistent malicious activity or campaign correlation
## Neighborhood Context
Subnet 13.49.141.132/24 exhibits low abuse density with no immediate sibling IPs flagged as high-risk. The broader network classification is "mostly clean" with inherited risk score of 2.
## Recommended Actions
1. Allow Traffic: This IP operates legitimate AWS infrastructure with proper email authentication and low abuse indicators
2. Monitor SSH Access: Standard SSH service on port 22; ensure inbound SSH is restricted to authorized management ranges if applicable
3. DNSBL Review: Investigate the 2 DNSBL listings if they impact legitimate traffic flows; verify listing reasons
4. No Block Required: Risk profile does not warrant blocking; treat as trusted cloud infrastructure
## Intelligence Confidence
High confidence in AWS ownership and infrastructure classification. Moderate confidence on blacklist activity due to intermittent nature of observations. No actionable threat indicators requiring immediate defensive response.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services Sweden |
| ASN | AS16509 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-13-49-141-132.eu-north-1.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-13-49-141-132.eu-north-1.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.0 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 45% | 1 | 8 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 26% | 10 | 23 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:39 UTC |
| Last Seen | 2026-06-26 22:11:13 UTC |
| Profile Built | 2026-06-27 18:23:33 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 36 |
Full dossier details are available via our API.