IPDebrief

18.226.62.39

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 18.226.62.39/32

## Executive Summary

IP address 18.226.62.39 is a legitimate Amazon Web Services (AWS) EC2 instance located in the US-East-2 (Ohio) region. While the risk score registers at 50 (Moderate Risk), the IP demonstrates no active threat indicators, no open services, and operates within a clean subnet environment. The profile indicates this is infrastructure-level cloud infrastructure with no evidence of malicious activity.

---

## Ownership & Infrastructure Profile

---

## DNS & Hostname Resolution

The IP resolves to a canonical AWS EC2 hostname:

---

## Threat Intelligence Assessment

Risk Score: 50 (Moderate Risk)

Abuse Confidence Score: Not calculated

Blacklist Status: 0/0 lists

Threat Indicators:

Service Status:

---

## Neighborhood Analysis (Subnet: 18.226.62.0/24)

---

## Relationship Graph

The IP maintains relationships primarily through DNS associations and network topology:

---

## Observation History

Historical signals from June 17-22, 2026 indicate:

---

## Recommended Security Actions

Firewall Rules

Based on the risk profile, the following rules are recommended:

iptables:

```bash

iptables -A INPUT -s 18.226.62.39 -j DROP

```

nftables:

```bash

nft add rule inet filter input ip saddr 18.226.62.39 drop

```

nginx:

```nginx

deny 18.226.62.39;

```

pfSense:

```

18.226.62.39/32

```

Cloudflare WAF:

```json

{

"description": "Block 18.226.62.39 β€” IPDebrief risk score 50",

"action": "block",

"filter": {

"expression": "ip.src eq 18.226.62.39"

}

}

```

AWS WAF:

```json

{

"Addresses": ["18.226.62.39/32"],

"Description": "IPDebrief risk 50"

}

```

---

## Analyst Notes

This IP address presents a moderate risk classification primarily due to its association with the broader AWS infrastructure network. The risk score of 50 is elevated relative to the absence of active threat indicators, which suggests the classification may be conservative or based on network-level heuristics rather than observed malicious behavior.

Key Observations:

1. No services or open ports detected

2. Clean neighborhood classification

3. No blacklist associations

4. Legitimate AWS EC2 hostname

5. DNSSEC and email authentication properly configured

Recommendation: Given the lack of active threat indicators and the clean operational profile, blocking this IP at the network perimeter is recommended only if correlation with other threat intelligence signals warrants it. The absence of open services and malicious activity suggests this may be legitimate cloud infrastructure. Monitor for any changes in behavior or service activation.

---

*Intelligence generated: IPDebrief Platform | Classification: Internal Use*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionOH
CityColumbus
Timezoneβ€”
Latitude39.96
Longitude-83.00

🏒 Ownership & Registration

OrganizationAmazon Technologies Inc.
ASNAS16509
Network NameAT-88-Z
CIDR Block18.32.0.0/11
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRec2-18-226-62-39.us-east-2.compute.amazonaws.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesec2-18-226-62-39.us-east-2.compute.amazonaws.com

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierTier 3 β€” Basic operator with some routing infrastructure
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
24%
22
routing
17%
11
services
17%
11
ownership
35%
23
reputation
17%
12
geolocation
35%
23
Overall24%912
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-06-16 18:32:01 UTC
Last Seen2026-06-22 00:41:40 UTC
Profile Built2026-06-22 00:53:48 UTC
Data FreshnessLive
Signal Types20
Total Observations24
πŸ” 20 signal types Β· 24 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.