IPDebrief

16.78.23.247

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# INTELLIGENCE BRIEFING: 16.78.23.247/32

## EXECUTIVE SUMMARY

IP address 16.78.23.247 is a cloud infrastructure endpoint operating within Amazon Web Services Jakarta (ap-southeast-3) region. The IP carries a moderate risk score of 50 with no active threat indicators. No services are publicly exposed, and the endpoint is properly firewalled. Historical data shows DNS blacklist presence on 2 of 8 threat intelligence feeds with high severity ratings.

---

## INFRASTRUCTURE PROFILE

Ownership: Amazon Data Services Jakarta (AMAZON-CGK)

ASN: 16509 | Network Block: 16.78.0.0/16

Geolocation: Jakarta, Indonesia (ID)

Infrastructure Type: CloudCompute (AWS EC2)

Service Status: Firewalled / No Services Detected

Network Classification: Cloud Provider Infrastructure

The IP resolves to hostname `ec2-16-78-23-247.ap-southeast-3.compute.amazonaws.com` with forward DNS resolution confirmed. PTR records align with expected AWS naming convention for the ap-southeast-3 (Jakarta) region.

---

## RISK ASSESSMENT

Overall Risk Score: 50 (Moderate Risk)

Threat Indicators: None

Blacklist Status: Listed on 2 of 8 threat intelligence feeds

Abuse Confidence Score: Not applicable (cloud infrastructure)

Risk Factors:

Mitigating Factors:

---

## OBSERVATION HISTORY

Total observations: 19 signals collected across monitoring period

Key Historical Events:

Temporal analysis indicates no persistent malicious activity. The IP shows zero threat persistence days and zero correlation to known campaigns.

---

## NETWORK NEIGHBORHOOD

Subnet: 16.78.23.247/24

Abuse Density: 0.0

Neighbor Count: 0 active siblings detected

No adjacent IPs in the /24 subnet exhibit elevated risk profiles or abuse indicators. The subnet demonstrates clean security posture typical of AWS infrastructure.

---

## RELATIONSHIP MAPPING

The IP maintains associations with:

---

## RECOMMENDED ACTIONS

Given the moderate risk profile and blacklist presence, the following firewall rules are recommended for defensive posture:

PlatformRule
**iptables**`iptables -A INPUT -s 16.78.23.247 -j DROP`
**nftables**`nft add rule inet filter input ip saddr 16.78.23.247 drop`
**nginx**`deny 16.78.23.247;`
**pfSense**`16.78.23.247/32`
**Cloudflare WAF**Block IP with expression `ip.src eq 16.78.23.247`
**AWS WAF**`Addresses: ["16.78.23.247/32"]`

Note: These recommendations are probabilistic and should be combined with other security signals before implementation.

---

## ANALYST NOTES

This IP represents standard AWS cloud infrastructure with no active threat indicators. The blacklist presence warrants monitoring but does not indicate active exploitation. The moderate risk score primarily reflects DNS reputation data rather than active malicious behavior. Continue monitoring for changes in service exposure or threat feed associations.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇮🇩 Indonesia
RegionJK
CityJakarta
TimezoneAsia/Jakarta
Latitude-6.18
Longitude106.85

🏢 Ownership & Registration

OrganizationAmazon Data Services Jakarta
ASNAS16509
Network NameAMAZON-CGK
CIDR Block16.78.0.0/16
RIRARIN
CountryIndonesia
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRec2-16-78-23-247.ap-southeast-3.compute.amazonaws.com
Forward ConfirmedYes — FCrDNS verified
Forward Hostnamesec2-16-78-23-247.ap-southeast-3.compute.amazonaws.com

🔐 DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 — Basic operator with some routing infrastructure
CloudHosting

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS16509
Network Prefix16.78.0.0/16
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
23
routing
13%
11
services
19%
22
ownership
27%
23
reputation
13%
12
geolocation
27%
23
Overall21%1014
Coverage: 6/6 dimensions · Data sufficiency: sufficient
Data CoherenceMixed Signals (68%) — 2 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: ID, US
⚠ TLS certificate claims US but primary geo says ID

📅 Observation Timeline 🔄 Live

First Seen2026-07-07 12:34:52 UTC
Last Seen2026-08-27 01:22:11 UTC
Profile Built2026-08-29 06:40:13 UTC
Data FreshnessLive
Signal Types25
Total Observations28
🔍 25 signal types · 28 observations collected
This report is generated from 25+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 16.78.23.247

Who owns the IP address 16.78.23.247?

16.78.23.247 is registered to Amazon Data Services Jakarta. The address falls within the 16.78.0.0/16 network block. Registration is held at ARIN.

Where is 16.78.23.247 located?

Geolocation data places 16.78.23.247 in Jakarta, JK, Indonesia. The local time zone is Asia/Jakarta. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 16.78.23.247 malicious or safe?

16.78.23.247 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 16.78.23.247?

The reverse DNS (PTR) record for 16.78.23.247 is ec2-16-78-23-247.ap-southeast-3.compute.amazonaws.com. This hostname is forward-confirmed, meaning it resolves back to the same address.

Is 16.78.23.247 a VPN, proxy, or data center address?

16.78.23.247 is classified as cloud infrastructure and hosting infrastructure based on network ownership and behavioural analysis.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.