# INTELLIGENCE BRIEFING: 18.203.84.147
Classification: AWS Cloud Compute Infrastructure | Date: June 2026 | Risk Level: LOW
---
## EXECUTIVE SUMMARY
IP address 18.203.84.147 is a cloud infrastructure endpoint belonging to Amazon Web Services (AWS) Ireland datacenter (eu-west-1). The IP exhibits a low-risk profile with no active threat indicators, zero blacklist entries, and minimal neighborhood abuse density. The asset is classified as a single-service host (cloud compute) with legitimate DNS and TLS infrastructure.
---
## ASSET IDENTIFICATION
| Attribute | Value |
|---|---|
| **IP Address** | 18.203.84.147 |
| **Network** | 18.202.0.0/15 (AMAZON-DUB) |
| **ASN** | 16509 (Amazon Data Services Ireland Limited) |
| **Location** | Dublin, Ireland (53.35°N, -6.26°W) |
| **Infrastructure Type** | CloudCompute (AWS EC2) |
| **ISP/Provider** | Amazon Web Services |
| **RIR** | ARIN |
---
## NETWORK CLASSIFICATION
The IP is classified as CloudCompute infrastructure with the following characteristics:
- Is Cloud: Yes (AWS EC2 instance)
- Is Hosting: Yes
- Is CDN: No
- Is Proxy/Tor/VPN: No
- Service Purpose: Single-Service Host
Control Plane Indicators:
- Origin ASN: 16509
- BGP Prefix: 18.202.0.0/15
- DNSSEC: Valid
- DNSBL Listed: 0/8 lists
- Operator Score: 0.2609 (Basic)
---
## THREAT ASSESSMENT
Risk Score: 0/100 | Reputation: Low Risk
Threat Indicators:
- No known attacker signatures
- No spam source association
- Not a Tor exit node
- Zero blacklist entries
- No persistent malicious activity detected
- Threat observation count: 1 (non-malicious)
Campaign Correlation: None detected. No certificate matches, banner matches, or correlated IPs identified.
---
## INFRASTRUCTURE DETAILS
DNS Resolution:
- PTR: ec2-18-203-84-147.eu-west-1.compute.amazonaws.com
- Forward Resolution: Confirmed
- Hosted Domain: amazonaws.com
Active Services:
- Port 8443/tcp (https-alt)
TLS Certificate:
- Issuer: Sectigo Public Server Authentication CA OV R36 (Sectigo Limited, GB)
- Subject: production-c7gn-large-aws-ie-dub-83454fb0.gen-vpn.com
- Organization: Gen Digital Inc. (Arizona, US)
- Not Self-Signed
Email Authentication:
- SPF: Configured
- DMARC: Configured
---
## OBSERVATION HISTORY (24 Signals)
Recent observations confirm stable cloud infrastructure characteristics:
1. Geolocation: Consistent Dublin, IE placement via multi-signal inference (confidence: 0.56)
2. Network Classification: AWS cloud infrastructure identified (confidence: 0.90)
3. Operator Assessment: Basic classification (raw score: 0.3)
4. Blacklist Status: No listings detected across 8 threat feeds
5. DNS: gen-vpn.com domain observed with standard email authentication
Temporal Analysis:
- Ownership changes: 0
- Threat persistence days: 0
- Classification: Not persistently malicious
---
## NETWORK NEIGHBORHOOD (18.203.84.0/24)
- Subnet Abuse Density: 0 (mostly clean)
- Inherited Risk: 2 (low)
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
The /24 subnet shows minimal abuse activity with one active sibling IP and no high-risk neighbors.
---
## RELATIONSHIP MAPPING
34 relationships identified, primarily:
- Network associations: AMAZON-DUB (multiple entries)
- DNS associations: ec2-18-203-84-147.eu-west-1.compute.amazonaws.com
- Cloud infrastructure relationships
No suspicious external entity associations detected.
---
## RECOMMENDATIONS
For SOC Analysts:
1. No Action Required: This IP represents legitimate AWS cloud infrastructure with no threat indicators.
2. Allow Traffic: Standard egress/ingress rules for AWS EC2 instances apply.
3. Monitor TLS Certificates: Certificate subject indicates Gen Digital Inc. usage (cloud service provider).
4. Baseline Behavior: Establish normal traffic patterns for this AWS EC2 endpoint.
Firewall Rules: No blocking recommended. Standard cloud provider IP allowlisting applies.
---
Analysis Notes: This IP is part of AWS's Dublin datacenter infrastructure. The TLS certificate subject (Gen Digital Inc.) indicates this host may be utilized by a cloud service provider or hosting partner. The clean threat profile and standard AWS network classification support continued monitoring without intervention.
---
*Generated via IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Amazon Data Services Ireland Limited |
| ASN | AS16509 |
| Network Name | AMAZON-DUB |
| CIDR Block | 18.202.0.0/15 |
| RIR | ARIN |
| Country | Ireland |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ec2-18-203-84-147.eu-west-1.compute.amazonaws.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ec2-18-203-84-147.eu-west-1.compute.amazonaws.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | 1/2 domains |
| DMARC | 1/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 8443 | https-alt | tcp | โ |
| Closed Ports | 22, 25, 80, 443, 3389, 8080 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | production-c7gn-large-aws-ie-dub-83454fb0.gen-vpn.com |
| Valid From | 2026-05-20T00:00:00+00:00 |
| Valid Until | 2026-12-04T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 198 days |
| Serial Number | 1B1901872990F15F0C963B2DACF780E8 |
| Thumbprint | 8C4590D13C029FAFEB4C3701E862C67949CBBE4E |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Mixed Signals (68%) โ 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ TLS certificate claims US but primary geo says IE
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-28 23:51:09 UTC |
| Last Seen | 2026-06-29 05:57:45 UTC |
| Profile Built | 2026-06-29 05:59:48 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 26 |
Full dossier details are available via our API.