IP address 18.218.170.194 was identified as a low-risk endpoint owned by Amazon Technologies Inc. (ASN 16509). The address was registered within the 18.32.0.0/11 block and geolocated to Columbus, Ohio, US. Reverse DNS resolution confirmed the hostname ec2-18-218-170-194.us-east-2.compute.amazonaws.com, indicating an EC2 instance in us-east-2.
Threat intelligence analysis showed no associated risk indicators. The IP returned zero blacklist associations and reported no activity against known threat feeds or campaigns. Risk scoring remained low, with zero values assigned for provider, authority, and stability metrics.
Network observation logs indicated an active HTTPS service on port 443. TLS certificate analysis revealed the endpoint served the Samsung Electronics OCF Server SubCA issuing certificates for *.samsungiotcloud.com.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Technologies Inc. |
| ASN | AS16509 |
| Network Name | AT-88-Z |
| CIDR Block | 18.32.0.0/11 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-18-218-170-194.us-east-2.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-18-218-170-194.us-east-2.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | *.samsungiotcloud.com |
| Valid From | 2020-03-18T07:40:32+00:00 |
| Valid Until | 2035-04-09T07:40:32+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256ECDSA |
| Validity Period | 5500 days |
| Serial Number | 33DEF0C83047D74E |
| Thumbprint | 30AA82E4144123E889C449CD1F47CDC2F811A97D |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 35% | 2 | 2 |
| Overall | 18% | 5 | 5 |
| Data Coherence | Mixed Signals (68%) β 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
β TLS certificate claims KR but primary geo says US
π Observation Timeline π Live
| First Seen | 2026-08-29 14:35:07 UTC |
| Last Seen | 2026-08-29 14:35:07 UTC |
| Profile Built | 2026-08-29 14:47:41 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 24 |
Full dossier details are available via our API.