IP Intelligence Briefing: 177.71.251.172/32
*Generated via IPDebrief Analysis*
---
**Core Profile**
- Risk Score: 50 (Moderate Risk)
- Ownership: Registered to A100 ROW SERVICOS DE DADOS BRASIL LTDA (ASN 16509, LACNIC).
- Geolocation: Located in São Paulo, Brazil (BR) via inferred coordinates, though ICMP validation failed (network firewall may block probes).
- Network Role: Amazon Web Services (AWS) infrastructure.
- Threat Indicators: No malicious activity detected (no abuse confidence, blacklists, or campaigns).
---
**Observation History**
- Last 30 Days: No persistent threat signals.
- ICMP Validation: Failed due to potential firewall blocking, limiting geo-verification accuracy.
- Subnet Analysis: Clean subnet (177.71.251.172/24) with 0 abuse density and no malicious neighbors.
---
**Relationships & Context**
- DNS Associations: Linked to AWS EC2 instance `ec2-177-71-251-172.sa-east-1.compute.amazonaws.com`.
- Network Connections: Part of AWS infrastructure (ASN 16509), suggesting legitimate cloud-hosted services.
- No Correlated Threats: No shared indicators with known malicious IPs or campaigns.
---
**Recommended Actions**
- Firewall Rules:
- iptables: `iptables -A INPUT -s 177.71.251.172 -j DROP`
- AWS WAF: Block IP with rule `{"Addresses":["177.71.251.172/32"], "Description":"IPDebrief risk 50"}`
- Monitoring: Verify AWS instance activity and access controls, as the IP is associated with cloud infrastructure.
---
**Conclusion**
This IP is associated with AWS infrastructure and shows no direct malicious indicators. The moderate risk score and clean subnet suggest it may be a legitimate cloud resource. However, the failed ICMP validation and lack of geo-verification warrant further investigation into its network behavior and access policies. SOC teams should monitor for unexpected traffic patterns or deviations from AWS baseline behavior.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | A100 ROW SERVICOS DE DADOS BRASIL LTDA |
| ASN | AS16509 |
| Network Name | 170475 |
| CIDR Block | 177.71.128.0/17 |
| RIR | LACNIC |
| Country | BR |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | ec2-177-71-251-172.sa-east-1.compute.amazonaws.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ec2-177-71-251-172.sa-east-1.compute.amazonaws.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 8080 | http-alt | tcp | โ |
| Closed Ports | 22, 25, 80, 443, 3389, 8443 (1 open / 7 scanned) | ||
| Server | nginx/1.20.1 |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 19% | 2 | 2 |
| ownership | 30% | 3 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 24% | 2 | 3 |
| Overall | 25% | 12 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-29 18:14:26 UTC |
| Last Seen | 2026-06-29 06:37:31 UTC |
| Profile Built | 2026-06-29 07:00:59 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 32 |
Full dossier details are available via our API.