The target IP 18.239.176.188 was identified as Amazon CloudFront infrastructure under ASN 16509. Ownership records linked the address to Amazon.com, Inc. in Boston, US, though geolocation data flagged a contradiction against RTT physics measurements. The endpoint operated standard web services on ports 80 and 443 with a CloudFront server banner and valid TLS certificates issued by Amazon RSA 2048 M04.
Threat analysis classified the IP as Low Risk with a Risk Score of 25. No blacklist entries were found, and the host was not marked as a known attacker, spam source, or Tor exit. Behavioral logs recorded zero WAF violations or honeypot hits. Despite a clean reputation, the threat actor profile tagged the host as "suspicious" due to signal inconsistencies regarding origin and geolocation.
The immediate neighborhood (18.239.176.0/24) remained mostly clean with an abuse density of 0.1333. SOC analysts were advised to monitor the IP for changes due to the presence of signal contradictions, though no immediate firewall rules were recommended.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon.com, Inc. |
| ASN | AS16509 |
| Network Name | AMAZON-CF |
| CIDR Block | 18.238.0.0/15 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | server-18-239-176-188.bos50.r.cloudfront.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | server-18-239-176-188.bos50.r.cloudfront.net |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | 2/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Present |
| Domains Checked | 2 domains |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | CloudFront |
| HTTP Title | β |
π TLS Certificate
| SANs | *.cloudfront.netcloudfront.net |
| Valid From | 2026-08-25T00:00:00+00:00 |
| Valid Until | 2027-03-10T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 197 days |
| Serial Number | 015E89F2D093DD92CD82A78C09A033C6 |
| Thumbprint | 5E9C8C0323F32C16F1D3F82DAE8E8E2D88E96056 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 37% | 2 | 6 |
| routing | 13% | 1 | 1 |
| services | 27% | 2 | 4 |
| ownership | 33% | 2 | 4 |
| reputation | 26% | 1 | 4 |
| geolocation | 27% | 2 | 4 |
| Overall | 27% | 10 | 23 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-09-04 10:23:29 UTC |
| Last Seen | 2026-09-25 03:02:26 UTC |
| Profile Built | 2026-09-25 03:16:23 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 44 |
Full dossier details are available via our API.