IPDebrief

18.191.18.233

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 18.191.18.233

Classification: Cloud Infrastructure (AWS EC2)

Risk Level: Low Risk (Score: 25/100)

Date: Current Analysis

Analyst: IPDebrief Intelligence

---

## Executive Summary

IP address 18.191.18.233 is a legitimate Amazon Web Services (AWS) EC2 instance located in the US East Region (Ohio). The address exhibits standard cloud infrastructure characteristics with no malicious indicators. No immediate defensive action required.

---

## Ownership and Infrastructure

The IP is associated with AWS cloud infrastructure and resolves to a standard EC2 hostname pattern. Forward DNS resolution confirms the address is properly registered within the AWS DNS infrastructure.

---

## Threat Assessment

Risk Score: 25 (Low Risk)

Abuse Confidence: Not flagged

Blacklist Status: Clean (0 blacklists)

Campaign Indicators: None

Key Findings:

---

## Network Role and Services

Infrastructure Classification:

Service Status: Firewalled / No Services

---

## Neighborhood Analysis

Subnet: 18.191.18.233/24

Abuse Density: 0 (Low)

Classification: Mostly Clean

Total Siblings: 1

Active Siblings: 1

Threat Siblings: 1

The /24 subnet exhibits minimal abuse density, consistent with AWS infrastructure patterns.

---

## Historical Signals

Observation Count: 22 signals

Signal Timeline: Recent observations (2026-08-12)

Geolocation Consistency: Columbus, OH, US (multi-signal inference)

Operator Score: Basic (0.2609)

Ownership Stability: No ownership changes detected

Threat Persistence: 0 days (no persistent malicious activity)

Historical analysis indicates stable cloud infrastructure with no degradation in risk profile over the observation period.

---

## Relationships

Network Associations: AT-88-Z (Amazon)

DNS Associations: ec2-18-191-18-233.us-east-2.compute.amazonaws.com

Certificate Associations: None

Campaign Correlations: None

The IP maintains expected relationships within the AWS ecosystem with no suspicious external associations.

---

## Recommended Actions

Security Recommendations: None

Firewall Rules: Not required

Analysis: The IP address demonstrates standard cloud infrastructure behavior with no malicious indicators. No blocking or monitoring actions are recommended at this time. Standard cloud traffic inspection protocols apply.

---

## Conclusion

IP 18.191.18.233 is a legitimate AWS EC2 instance with low risk characteristics. The address shows consistent geolocation data, proper DNS registration, and no threat indicators. SOC teams may treat this as benign cloud infrastructure unless additional context suggests otherwise.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionOH
CityColumbus
TimezoneAmerica/New_York
Latitude39.96
Longitude-83.00

🏒 Ownership & Registration

OrganizationAmazon Technologies Inc.
ASNAS16509
Network NameAT-88-Z
CIDR Block18.32.0.0/11
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRec2-18-191-18-233.us-east-2.compute.amazonaws.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesec2-18-191-18-233.us-east-2.compute.amazonaws.com

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 β€” Basic operator with some routing infrastructure
Cloud

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
31%
24
routing
13%
11
services
19%
22
ownership
27%
23
reputation
26%
13
geolocation
27%
23
Overall24%1016
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-27 15:46:25 UTC
Last Seen2026-08-12 21:35:36 UTC
Profile Built2026-08-12 21:45:43 UTC
Data FreshnessLive
Signal Types23
Total Observations23
πŸ” 23 signal types Β· 23 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.