INTELLIGENCE BRIEFING: IP ADDRESS 18.239.166.202
Date: 2026-09-26
Classification: Low Risk / Infrastructure
Risk Score: 25
Executive Summary
The target IP address is identified as part of Amazon CloudFront infrastructure. Ownership is attributed to Amazon.com, Inc. (AS16509) within the AMAZON-CF network. While the subnet is classified as mostly clean with low abuse density, specific control plane and geolocation contradictions warrant monitoring.
Technical Profile
* Ownership: Amazon.com, Inc., Netname: AMAZON-CF, RIR: ARIN.
* Network Role: Web Server (CDN/Cloud).
* Open Ports: TCP 80 (HTTP), TCP 443 (HTTPS).
* TLS Certificate: Issued by Amazon RSA 2048 M04 for *.cloudfront.net.
* DNS Hygiene: SPF and DMARC records present and valid.
* Route Stability: Marked as unstable within the last 30 days.
Threat and Reputation Assessment
* Reputation: Low Risk.
* Threat Indicators: No known attack campaigns, spam sources, or Tor exit node activity.
* Blacklists: Listed on one DNSBL out of eight total lists checked.
* Behavioral: Zero WAF violations, no honeypot hits, and no enumeration strikes observed.
Anomalies and Contradictions
* Geolocation: Data indicates a claimed location of Boston, MA, but RTT physics measurements (22ms) contradict the 7625km distance from the probe.
* Control Plane: Route changes recorded with no IRR consistency validation.
* Confidence: Overall confidence labeled as Very Low (0.1833) due to data contradictions.
Recommendation
Treat traffic as benign infrastructure but monitor for changes. The IP is associated with standard CloudFront services; allow standard web traffic but flag for review if behavior deviates from established CDN patterns or if the specific DNSBL listing becomes active.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon.com, Inc. |
| ASN | AS16509 |
| Network Name | AMAZON-CF |
| CIDR Block | 18.238.0.0/15 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | server-18-239-166-202.bos50.r.cloudfront.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | server-18-239-166-202.bos50.r.cloudfront.net |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | 2/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Present |
| Domains Checked | 2 domains |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | CloudFront |
| HTTP Title | β |
π TLS Certificate
| SANs | *.cloudfront.netcloudfront.net |
| Valid From | 2026-08-25T00:00:00+00:00 |
| Valid Until | 2027-03-10T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 197 days |
| Serial Number | 015E89F2D093DD92CD82A78C09A033C6 |
| Thumbprint | 5E9C8C0323F32C16F1D3F82DAE8E8E2D88E96056 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 27% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 19% | 2 | 2 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-09-12 01:29:14 UTC |
| Last Seen | 2026-09-26 00:01:31 UTC |
| Profile Built | 2026-09-26 00:09:59 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 37 |
Full dossier details are available via our API.