IPDebrief

18.232.121.80

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 18.232.121.80/32

Classification: Cloud Infrastructure Host (AWS EC2)

Date: 2026-08-05

Analyst: IPDebrief Intelligence Team

---

## Executive Summary

IP 18.232.121.80 is an Amazon Web Services EC2 instance hosted in Ashburn, Virginia (US). The IP registers a moderate risk score of 65/100, primarily driven by elevated risk classification. However, the address belongs to a clean subnet (abuse density: 0) with no adjacent threat siblings and no persistent malicious indicators. The instance is configured with SSH (port 22) and resolves to ec2-18-232-121-80.compute-1.amazonaws.com.

---

## Technical Profile

Ownership & Registration:

Geolocation:

Network Classification:

Active Services:

---

## Threat Indicators Assessment

Current Threat Status: No active threat indicators detected.

IndicatorStatus
Known AttackerNo
Tor Exit NodeNo
Spam SourceNo
Known CampaignNo
Blacklist Count0
DNSBL Listed3/8 lists
Threat Persistence Days0
Is Persistently MaliciousNo

---

## Historical Observations

Signal History (20 observations):

Temporal Analysis:

---

## Neighborhood Analysis

Subnet: 18.232.121.80/24

MetricValue
Abuse Density0 (Clean)
ClassificationClean
Active Siblings0
Threat Siblings0
High Risk Neighbors0
Medium Risk Neighbors0

The IP resides in a clean subnet with no adjacent threat activity.

---

## Relationships Graph

Total Relationships: 14

---

## Recommended Security Actions

Risk Score: 65/100 (Moderate Risk)

Primary Recommendation: Increase logging verbosity and review recent activity from this IP.

Firewall Rule Recommendations:

```bash

# iptables

iptables -A INPUT -s 18.232.121.80 -j DROP

# nftables

nft add rule inet filter input ip saddr 18.232.121.80 drop

# nginx

deny 18.232.121.80;

# pfSense

18.232.121.80/32

# Cloudflare WAF

{"description":"Block 18.232.121.80 β€” IPDebrief risk score 65","action":"block","filter":{"expression":"ip.src eq 18.232.121.80"}}

# AWS WAF

{"Addresses":["18.232.121.80/32"],"Description":"IPDebrief risk 65"}

```

---

## Assessment Notes

While the IP carries a moderate risk score, contextual analysis suggests this is a standard AWS cloud infrastructure host rather than a malicious actor. The clean neighborhood classification, absence of persistent threat indicators, and legitimate AWS ownership support a benign classification. However, the elevated risk score warrants monitoring, particularly given the open SSH service.

Recommended Action: Monitor for suspicious activity patterns. Block only if specific malicious behavior is observed. Consider implementing rate limiting on SSH connections from this IP range if not already in place.

---

*Intel generated by IPDebrief Intelligence Platform. Data current as of 2026-08-05.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionVA
CityAshburn
TimezoneAmerica/New_York
Latitude39.04
Longitude-77.49

🏒 Ownership & Registration

OrganizationAmazon Technologies Inc.
ASNAS14618
Network NameAT-88-Z
CIDR Block18.32.0.0/11
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRec2-18-232-121-80.compute-1.amazonaws.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesec2-18-232-121-80.compute-1.amazonaws.com

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeSingle-Service Host
Network TierTier 3 β€” Basic operator with some routing infrastructure
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_8.7

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
32%
23
routing
13%
11
services
19%
22
ownership
27%
23
reputation
17%
12
geolocation
27%
23
Overall23%1014
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-29 10:33:42 UTC
Last Seen2026-08-12 23:21:53 UTC
Profile Built2026-08-12 23:34:25 UTC
Data FreshnessLive
Signal Types20
Total Observations20
πŸ” 20 signal types Β· 20 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.