# IP Intelligence Briefing: 18.97.5.94/32
Classification: LOW RISK | Reputation Score: 25/100 | Status: Active
## Executive Summary
IP address 18.97.5.94 is a low-risk infrastructure address hosted by Amazon Web Services. The IP exhibits no active threat indicators and is associated with Amazon's cloud infrastructure in Ashburn, Virginia. Recommended action: Monitor but no immediate blocking required.
## Infrastructure Profile
- IP: 18.97.5.94/32
- Organization: Amazon Technologies Inc.
- ASN: 14618 (Amazon.com, Inc.)
- Network Block: 18.32.0.0/11
- Geolocation: Ashburn, Virginia, US (39.04°N, -77.49°W)
- Infrastructure Type: Cloud/CDN (AWS infrastructure)
- Status: Firewalled / No Services Detected
## Threat Assessment
| Metric | Status |
|---|---|
| Risk Score | 25 (Low) |
| Blacklist Count | 0 |
| Tor Exit Node | No |
| Known Attacker | No |
| Spam Source | No |
| Known Campaigns | None |
| Threat Persistence Days | 0 |
| DNSBL Listings | 1 of 8 total lists |
The IP shows no evidence of malicious activity. No threat indicators were detected across multiple signal sources.
## Network Context
Subnet Analysis (18.97.5.0/24):
- Abuse Density: 0.5 (Moderate)
- Classification: Mixed
- Total Siblings: 7
- Active Siblings: 3
Neighbor Risk Distribution:
- High Risk (40+): 3 IPs
- Medium Risk (25): 3 IPs
- Low Risk (0-24): 4 IPs
## DNS Intelligence
- PTR Record: scanner-18-97-5-94.reposify.net
- Forward Resolution: reposify.net (1 record)
- Email Authentication: SPF and DMARC configured
- Associated Domain: reposify.net
The DNS infrastructure indicates legitimate service hosting with proper email authentication controls in place.
## Historical Observations
Recent signal history shows consistent low-risk behavior with no escalation in threat signals. Ownership has remained stable with no malicious activity detected over the observation period.
## Recommended Actions
No immediate action required. The IP presents as legitimate cloud infrastructure. Standard monitoring practices recommended.
Firewall Rules: Not recommended for this IP.
## SOC Analyst Notes
This address is part of Amazon's cloud infrastructure and appears to be legitimately hosted. The "scanner" hostname in DNS may indicate automated monitoring or legitimate scanning operations. With a risk score of 25 and no active threat indicators, this IP should be treated as benign infrastructure. Continue standard monitoring procedures.
Last Updated: Current intelligence data as of analysis date
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Technologies Inc. |
| ASN | AS14618 |
| Network Name | AT-88-Z |
| CIDR Block | 18.32.0.0/11 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | scanner-18-97-5-94.reposify.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | scanner-18-97-5-94.reposify.net |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 38% | 2 | 4 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 32% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 30% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-09 20:26:57 UTC |
| Last Seen | 2026-06-21 16:41:03 UTC |
| Profile Built | 2026-06-21 16:42:41 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.