IPDebrief

18.222.91.240

IP Intelligence Dossier
Your IP: 216.73.217.135
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 18.222.91.240/32

Classification: Low Risk / Cloud Infrastructure

Date: June 2026

Analyst: IPDebrief Intelligence Team

---

## Executive Summary

IP address 18.222.91.240 is a low-risk Amazon Web Services (AWS) EC2 instance located in Columbus, Ohio. The asset demonstrates stable cloud infrastructure characteristics with no active threat indicators. The IP carries a risk score of 25/100 and is classified as firewalled with no open services. One DNS blacklist listing was identified, representing a minor concern requiring monitoring.

## Ownership and Network Classification

The IP resolves to hostname `ec2-18-222-91-240.us-east-2.compute.amazonaws.com`, confirming its identity as a standard AWS EC2 compute instance.

## Threat Assessment

No active threat indicators detected. The IP does not appear in known malicious campaigns or threat feeds.

## Services and Network Role

The absence of open ports indicates the instance is properly configured with minimal service exposure, consistent with security best practices for cloud infrastructure.

## Observation History

Twenty-four observations were retrieved over the monitoring period. Key patterns include:

The history demonstrates stable ownership and network characteristics with no significant changes in threat profile.

## Neighborhood Analysis

Subnet 18.222.91.0/24 analysis indicates:

The neighborhood shows minimal abuse activity, with one threat sibling identified. This level of activity is normal for a large cloud provider subnet.

## Relationship Graph

Twenty-five relationships identified, comprising:

No malicious relationships or certificate associations detected.

## Recommended Actions

Based on the low-risk profile and cloud infrastructure classification, standard monitoring is recommended:

1. Allow Standard Traffic: No blocking required; this is legitimate AWS infrastructure

2. Monitor DNSBL: Track the single DNS blacklist listing for changes

3. Log Connections: Maintain connection logs for audit purposes

4. No Firewall Rules Required: No iptables/nftables rules necessary

## Conclusion

IP 18.222.91.240 represents standard AWS cloud infrastructure with a low-risk profile. The asset exhibits normal cloud compute behavior with no malicious indicators. SOC teams should treat this as a benign IP requiring standard monitoring rather than active threat response. The single DNSBL listing warrants periodic review but does not constitute an immediate security concern.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionOH
CityColumbus
TimezoneAmerica/New_York
Latitude39.96
Longitude-83.00

🏒 Ownership & Registration

OrganizationAmazon Technologies Inc.
ASNAS16509
Network NameAT-88-Z
CIDR Block18.32.0.0/11
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRec2-18-222-91-240.us-east-2.compute.amazonaws.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesec2-18-222-91-240.us-east-2.compute.amazonaws.com

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeSingle-Service Host
Network TierTier 3 β€” Basic operator with some routing infrastructure
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_7.4

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
24
routing
34%
23
services
26%
22
ownership
40%
35
reputation
26%
13
geolocation
25%
22
Overall30%1219
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-06-02 12:03:35 UTC
Last Seen2026-06-29 10:50:17 UTC
Profile Built2026-06-29 16:52:32 UTC
Data FreshnessLive
Signal Types25
Total Observations27
πŸ” 25 signal types Β· 27 observations collected
This report is generated from 25+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.