# IP Intelligence Briefing: 18.191.18.233
Classification: Cloud Infrastructure (AWS EC2)
Risk Level: Low Risk (Score: 25/100)
Date: Current Analysis
Analyst: IPDebrief Intelligence
---
## Executive Summary
IP address 18.191.18.233 is a legitimate Amazon Web Services (AWS) EC2 instance located in the US East Region (Ohio). The address exhibits standard cloud infrastructure characteristics with no malicious indicators. No immediate defensive action required.
---
## Ownership and Infrastructure
- Organization: Amazon Technologies Inc.
- Netname: AT-88-Z
- ASN: 16509
- CIDR Block: 18.32.0.0/11
- Network Type: Public Cloud (AWS)
- Location: Columbus, OH, US (Lat: 39.96, Lon: -83.00)
- Reverse DNS: ec2-18-191-18-233.us-east-2.compute.amazonaws.com
- Registration Authority: ARIN
The IP is associated with AWS cloud infrastructure and resolves to a standard EC2 hostname pattern. Forward DNS resolution confirms the address is properly registered within the AWS DNS infrastructure.
---
## Threat Assessment
Risk Score: 25 (Low Risk)
Abuse Confidence: Not flagged
Blacklist Status: Clean (0 blacklists)
Campaign Indicators: None
Key Findings:
- No known attacker reputation
- No Tor exit node association
- No spam source indicators
- No known threat campaigns correlated
- Threat indicators list: Empty
---
## Network Role and Services
Infrastructure Classification:
- Is Cloud: Yes
- Is CDN: No
- Is VPN: No
- Is Proxy: No
- Is Hosting: No
- Is Mobile: No
- Is Residential: No
Service Status: Firewalled / No Services
- No open ports detected
- No HTTP/HTTPS banner information
- No TLS certificates observed
- No service fingerprints identified
---
## Neighborhood Analysis
Subnet: 18.191.18.233/24
Abuse Density: 0 (Low)
Classification: Mostly Clean
Total Siblings: 1
Active Siblings: 1
Threat Siblings: 1
The /24 subnet exhibits minimal abuse density, consistent with AWS infrastructure patterns.
---
## Historical Signals
Observation Count: 22 signals
Signal Timeline: Recent observations (2026-08-12)
Geolocation Consistency: Columbus, OH, US (multi-signal inference)
Operator Score: Basic (0.2609)
Ownership Stability: No ownership changes detected
Threat Persistence: 0 days (no persistent malicious activity)
Historical analysis indicates stable cloud infrastructure with no degradation in risk profile over the observation period.
---
## Relationships
Network Associations: AT-88-Z (Amazon)
DNS Associations: ec2-18-191-18-233.us-east-2.compute.amazonaws.com
Certificate Associations: None
Campaign Correlations: None
The IP maintains expected relationships within the AWS ecosystem with no suspicious external associations.
---
## Recommended Actions
Security Recommendations: None
Firewall Rules: Not required
Analysis: The IP address demonstrates standard cloud infrastructure behavior with no malicious indicators. No blocking or monitoring actions are recommended at this time. Standard cloud traffic inspection protocols apply.
---
## Conclusion
IP 18.191.18.233 is a legitimate AWS EC2 instance with low risk characteristics. The address shows consistent geolocation data, proper DNS registration, and no threat indicators. SOC teams may treat this as benign cloud infrastructure unless additional context suggests otherwise.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Technologies Inc. |
| ASN | AS16509 |
| Network Name | AT-88-Z |
| CIDR Block | 18.32.0.0/11 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-18-191-18-233.us-east-2.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-18-191-18-233.us-east-2.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-27 15:46:25 UTC |
| Last Seen | 2026-08-12 21:35:36 UTC |
| Profile Built | 2026-08-12 21:45:43 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 23 |
Full dossier details are available via our API.