IP INTELLIGENCE BRIEFING: 16.28.56.185/32
Classification: LOW RISK β Legitimate Cloud Infrastructure
Date: 2026-08-13
Analyst: IPDebrief Intelligence Team
---
Executive Summary
IP address 16.28.56.185 resolves to Amazon Web Services (AWS) infrastructure in Cape Town, South Africa. The address exhibits low risk characteristics with a risk score of 25/100. The IP is registered to AMAZON-CPT (ASN 16509) within the 16.28.0.0/16 block. No malicious indicators, blacklisting, or attack attribution was observed during analysis.
---
Infrastructure Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 25 (Low Risk) |
| **Provider Score** | 0 |
| **Authority Score** | 0 |
| **ASN** | 16509 |
| **Organization** | Amazon Data Services South Africa (AMAZON-CPT) |
| **CIDR Block** | 16.28.0.0/16 |
| **Geolocation** | Cape Town, Western Cape, ZA |
| **Coordinates** | -33.93, 18.42 |
| **Timezone** | Africa/Johannesburg |
DNS Resolution: ec2-16-28-56-185.af-south-1.compute.amazonaws.com (forward confirmed)
Open Ports:
- Port 22/TCP (SSH) β OpenSSH 10.2p1 Ubuntu-2ubuntu3.5
---
Threat Assessment
Threat Indicators:
- Blacklist Count: 0
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Reputation Sources: None detected
- Known Campaigns: None
Risk Breakdown:
- Abuse Confidence Score: Not detected
- Pulsedive Risk: Not applicable
- Control Plane Risk: Basic operator classification
Campaign Correlation:
- Campaign Likelihood: Not detected
- Certificate Matches: 0
- Correlated IPs: 0
---
Observation History
Analysis revealed 16 historical observations as of 2026-08-13. Signals indicate:
- Geolocation: Consistent Cape Town, South Africa positioning with multi-source inference
- Network Activity: SSH service probe detected with Ubuntu-based OpenSSH version
- Ownership: No ownership changes detected; stability observed
- Malicious Activity: Zero threat persistence days; not persistently malicious
Temporal Analysis: No significant escalation in risk over the observation period.
---
Network Relationships
DNS Associations:
- ec2-16-28-56-185.af-south-1.compute.amazonaws.com (repeated entries)
Network Affiliations:
- AMAZON-CPT (16.28.0.0/16 block)
Relationship Count: 6 total relationships identified (DNS and network-level)
---
Neighborhood Analysis
Subnet: 16.28.56.185/24
- Neighbor Count: 0
- Abuse Density: 0%
- High Risk Neighbors: 0
- Medium Risk Neighbors: 0
- Low Risk Neighbors: 0
- Threat Siblings: 0
The immediate /24 subnet contains no additional observed IP activity or threat indicators.
---
Recommended Security Actions
Firewall/IPS Rules:
- No specific blocking rules recommended given low-risk profile
- Standard AWS infrastructure egress rules apply if needed
Monitoring Considerations:
- Monitor for unusual outbound traffic patterns (typical AWS behavior)
- SSH access to this host should be evaluated in context of organizational security policies
---
Conclusion
IP 16.28.56.185 is identified as legitimate AWS cloud infrastructure located in Cape Town, South Africa. The address shows no malicious activity, blacklisting, or threat indicators. The low risk score (25/100) and absence of abuse signals indicate this is a standard cloud-hosted service. No immediate blocking or mitigation action is warranted.
Status: CLEAR FOR MONITORING β No action required beyond standard baseline monitoring.
---
*Report generated using IPDebrief intelligence platform data. All findings are derived from observed signals and public intelligence sources.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services South Africa |
| ASN | AS16509 |
| Network Name | AMAZON-CPT |
| CIDR Block | 16.28.0.0/16 |
| RIR | ARIN |
| Country | South Africa |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-16-28-56-185.af-south-1.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-16-28-56-185.af-south-1.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_10.2p1 Ubuntu-2ubuntu3.5 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 21% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 19% | 2 | 2 |
| Overall | 19% | 10 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-08 10:21:30 UTC |
| Last Seen | 2026-08-27 11:23:24 UTC |
| Profile Built | 2026-08-29 04:31:55 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.