# IP Intelligence Briefing: 18.169.133.166/32
Date: 2026-06-21
Classification: LOW RISK
Risk Score: 25/100
## Executive Summary
IP 18.169.133.166 is an Amazon Web Services (AWS) EC2 instance deployed in the London region (eu-west-2). The address maintains a low-risk profile with no active threat indicators or malicious activity observed. Infrastructure classification indicates standard cloud compute infrastructure with no exposed services.
## Ownership and Geolocation
- Organization: Amazon Data Services UK (AS16509)
- Network: AMAZON-LHR (18.168.0.0/14)
- Location: London, England, GB (51.51°N, 0.13°W)
- Infrastructure Type: CloudCompute
- PTR Record: ec2-18-169-133-166.eu-west-2.compute.amazonaws.com
## Threat Assessment
- Reputation: Low Risk
- Abuse Confidence: Not applicable (cloud infrastructure)
- Blacklist Status: 1/8 DNSBL listings
- Known Campaigns: None
- Tor/Proxy/VPN: No
- Is Anycast: No
- Threat Persistence: 0 days
## Network Services
- Open Ports: None detected
- HTTP/HTTPS: No services exposed
- TLS Certificate: None
- Connection Status: Firewalled / No Services
## Historical Observations
23 signal observations recorded between 2026-06-16 and 2026-06-21. Observations consistently show:
- Basic operator score: 0.2609
- DNSSEC validation: Valid
- Geolocation validation: Plausible (ICMP validation blocked)
- No escalation in threat signals
- Average observation confidence: 0.32
## Network Relationships
- DNS Associations: 28 entries pointing to AWS EC2 hostname
- Network Associations: Multiple references to AMAZON-LHR network
- Related Entities: Standard AWS infrastructure relationships
## Neighborhood Analysis (18.169.133.0/24)
- Subnet Classification: Mostly Clean
- Abuse Density: 0 (minimal)
- Threat Siblings: 1
- Active Siblings: 1
- High/Medium Risk Neighbors: 0
## Recommended Actions
No specific firewall rules or blocking actions recommended. The IP represents legitimate AWS cloud infrastructure with no observed malicious activity. If traffic from this address is flagged for suspicious activity, investigate at the application level rather than implementing IP-level blocks.
## Intelligence Narrative
This IP address represents routine AWS cloud infrastructure in the UK region. The low risk score (25) and absence of threat indicators suggest legitimate cloud service operation. The subnet exhibits minimal abuse density with only one threat sibling, indicating the broader 18.169.133.0/24 network is operating normally. No evidence of malicious campaigns, spam operations, or known attacker attribution. SOC analysts may treat inbound/outbound traffic from this address as low-priority unless correlated with specific application-layer anomalies.
Status: Monitor as routine cloud infrastructure traffic
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Amazon Data Services UK |
| ASN | AS16509 |
| Network Name | AMAZON-LHR |
| CIDR Block | 18.168.0.0/14 |
| RIR | ARIN |
| Country | United Kingdom |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ec2-18-169-133-166.eu-west-2.compute.amazonaws.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ec2-18-169-133-166.eu-west-2.compute.amazonaws.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 21% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-27 01:07:07 UTC |
| Last Seen | 2026-06-29 03:40:23 UTC |
| Profile Built | 2026-06-29 03:42:25 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.