## IP Intelligence Briefing: 18.116.239.38/32
Classification: Legitimate Infrastructure (AWS Cloud)
Risk Assessment: Low Risk (Score: 25/100)
Date: Analysis completed
---
Ownership & Infrastructure
The IP address 18.116.239.38 is registered to Amazon Technologies Inc. (ASN 16509) within CIDR block 18.32.0.0/11 (network designation AT-88-Z). Geolocation data indicates Columbus, Ohio (US), with coordinates 39.96°N, 83°W. DNS resolution confirms the address resolves to ec2-18-116-239-38.us-east-2.compute.amazonaws.com, identifying this as an AWS EC2 instance in us-east-2 (Ohio) region.
Network Role & Services
Infrastructure classification confirms this is a single-service host within AWS cloud infrastructure. Open services include:
- SSH (port 22/tcp): Open with OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 banner
- TLS/HTTP: No active TLS certificates or HTTP content detected
Threat Indicators
No malicious activity detected:
- Abuse confidence: Not applicable (infrastructure trust)
- Blacklist count: 0
- Known attacker/Spam source: False
- Tor exit node: False
- Known campaigns: None
- Threat feeds: Empty
- DNSBL listings: 1 (operational DNSBL check)
Historical Observations
Analysis of 20 historical signal observations shows consistent infrastructure behavior with no escalation in risk profile. Key temporal indicators:
- Ownership changes: 0 (stable)
- Threat persistence days: 0
- Threat observation count: 0
- Persistence status: Not persistently malicious
Geolocation validation shows minor RTT anomalies (35ms vs 131.6ms minimum possible for 6,580km distance), but this is consistent with AWS anycast routing patterns and does not indicate spoofing.
Neighborhood Analysis
Subnet analysis for 18.116.239.0.0/24:
- Abuse density: 0 (clean)
- Threat siblings: 0
- Classification: Clean
- Inherited risk: 0
No neighboring IPs exhibit malicious behavior patterns.
Relationships
The IP maintains standard AWS infrastructure relationships:
- Network association: AT-88-Z
- DNS associations: ec2-18-116-239-38.us-east-2.compute.amazonaws.com (confirmed)
- No anomalous relationships to external organizations or subnets
---
Operational Summary
18.116.239.38 is a legitimate AWS EC2 instance with no threat indicators. The IP demonstrates stable operational characteristics consistent with cloud infrastructure hosting. The single open SSH port is typical for managed cloud instances. No firewall blocking is recommended unless the receiving system has specific security policies requiring SSH restrictions.
Recommendation: Allow traffic with standard security controls. No blocking actions required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Technologies Inc. |
| ASN | AS16509 |
| Network Name | AT-88-Z |
| CIDR Block | 18.32.0.0/11 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-18-116-239-38.us-east-2.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-18-116-239-38.us-east-2.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-09 14:17:45 UTC |
| Last Seen | 2026-06-23 00:56:23 UTC |
| Profile Built | 2026-06-21 16:32:33 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.