IPDebrief

18.209.86.113

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IPDEBRIEF INTELLIGENCE BRIEFING

Subject: 18.209.86.113/32

Classification: Low Risk Infrastructure IP

Date: 2026-06-16

Analyst: IPDebrief SOC Team

---

## EXECUTIVE SUMMARY

IP 18.209.86.113 is a low-risk infrastructure address belonging to Amazon Web Services (AWS). The IP is classified as a cloud compute resource with no active threat indicators. No immediate blocking action is recommended for defensive security operations.

---

## OWNERSHIP & ATTRIBUTION

AttributeValue
**Organization**Amazon Technologies Inc.
**ASN**14618 (AT-88-Z)
**CIDR Block**18.32.0.0/11
**Geolocation**Ashburn, VA, US
**Infrastructure Type**Cloud Compute (AWS)
**Registration**ARIN (2005-11-04)

---

## RISK ASSESSMENT

Overall Risk Score: 25/100 (Low Risk)

MetricScoreStatus
Risk Score25Low Risk
Provider Score0N/A
Authority Score0N/A
Stability Score0N/A
Abuse ConfidenceN/AN/A

Threat Indicators: None detected

---

## NETWORK PROFILE

Network Role: AWS Cloud Infrastructure

DNS Resolution:

Services: No open ports detected (firewalled infrastructure)

---

## GEOLOCATION VALIDATION

MetricValue
CountryUS
RegionVA
CityAshburn
Accuracy Radius150 km
Geo ConsensusValid
Geo PlausibleYes
Violation StatusICMP blocked - unable to validate

---

## HISTORICAL OBSERVATIONS

Total Observations: 23 signals

Recent Activity (2026-06-16):

Temporal Analysis:

---

## RELATIONSHIP GRAPH

Total Relationships: 25

Primary Associations:

No malicious entity relationships detected.

---

## NEIGHBORHOOD ANALYSIS

Subnet: 18.209.86.0/24

Assessment: No neighboring IPs show malicious activity.

---

## RECOMMENDED ACTIONS

Action TypeStatus
BlockingNot Recommended (Low Risk)
AllowlistingConsider for AWS infrastructure
MonitoringStandard traffic monitoring
Firewall RulesNone required

Rationale: This IP represents AWS infrastructure with no active threat indicators. Standard defensive posture for cloud provider IPs applies.

---

## INTELLIGENCE NARRATIVE

IP 18.209.86.113 is a legitimate AWS infrastructure address located in Ashburn, Virginia. The IP resolves to mxtoolbox.com email services and operates within the 18.32.0.0/11 AWS block. Historical analysis shows consistent ownership by Amazon Technologies Inc. since 2005 with no malicious activity patterns. The subnet demonstrates zero abuse density and no neighboring threat indicators. A single blacklisting event was observed on 2026-06-16 across 8 total lists, with high severity classification on one listing; however, the overall risk score remains low (25/100). No open ports are detected, consistent with firewall-hardened AWS infrastructure. No firewall blocking is recommended for this address. SOC teams should treat this as benign AWS traffic unless specific campaign indicators emerge.

---

END OF BRIEFING

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionVA
CityAshburn
TimezoneAmerica/New_York
Latitude39.04
Longitude-77.49

🏒 Ownership & Registration

OrganizationAmazon Technologies Inc.
ASNAS14618
Network NameAT-88-Z
CIDR Block18.32.0.0/11
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRkeeper-us-east-1d.mxtoolbox.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnameskeeper-us-east-1d.mxtoolbox.com

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 β€” Basic operator with some routing infrastructure
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
33%
24
routing
27%
23
services
19%
22
ownership
30%
34
reputation
13%
12
geolocation
31%
23
Overall25%1218
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-29 18:14:27 UTC
Last Seen2026-06-29 06:38:01 UTC
Profile Built2026-06-29 06:42:36 UTC
Data FreshnessLive
Signal Types24
Total Observations25
πŸ” 24 signal types Β· 25 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.