IPDebrief

3.112.199.65

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 3.112.199.65/32

Date: 2026-07-30

Classification: Moderate Risk

## Executive Summary

IP 3.112.199.65 is an Amazon Web Services EC2 instance registered to Amazon Data Services Japan (ASN 16509). The address carries a moderate risk score of 50 and is listed on 2 of 8 DNSBLs. While no active threat indicators were identified, the IP is recommended for blocking based on its risk profile and blacklist presence.

## Network Ownership & Classification

## Geolocation Analysis

Geolocation data presents conflicting signals:

The discrepancy in geolocation data warrants monitoring but does not indicate malicious intent by itself.

## Threat Assessment

Note: While the threat indicators section shows zero indicators, the control plane data indicates DNSBL listing on 2 of 8 lists, contributing to the moderate risk classification.

## Network Neighborhood Analysis

The /24 subnet shows no abuse density and no neighboring threat actors, suggesting this IP operates in isolation within its network segment.

## Relationship Graph

Three relationships identified:

1. DNS Association: ec2-3-112-199-65.ap-northeast-1.compute.amazonaws.com

2. Same Network: AMAZON-NRT

3. DNS Association: ec2-3-112-199-65.ap-northeast-1.compute.amazonaws.com

No additional infrastructure or organizational relationships detected beyond AWS ecosystem.

## Historical Observations

17 observations recorded as of 2026-07-30. Recent signals include:

No persistent malicious behavior observed. Threat persistence days: 0.

## Recommended Security Actions

Immediate Action: Block traffic from this IP address

Firewall Rules

iptables:

```

iptables -A INPUT -s 3.112.199.65 -j DROP

```

nftables:

```

nft add rule inet filter input ip saddr 3.112.199.65 drop

```

nginx:

```

deny 3.112.199.65;

```

pfSense:

```

3.112.199.65/32

```

Cloudflare WAF:

```json

{

"description": "Block 3.112.199.65 โ€” IPDebrief risk score 50",

"action": "block",

"filter": {

"expression": "ip.src eq 3.112.199.65"

}

}

```

AWS WAF:

```json

{

"Addresses": ["3.112.199.65/32"],

"Description": "IPDebrief risk 50"

}

```

## Intelligence Narrative

This IP address represents a standard AWS EC2 instance without active malicious indicators. The moderate risk score stems primarily from DNSBL listings rather than observed threat activity. The geolocation discrepancy between Tokyo, Japan (primary) and Chicago, US (transit) reflects the complex routing infrastructure of AWS's global network and does not indicate malicious activity.

The /24 subnet shows clean classification with zero abuse density and no sibling threats. No relationships extend beyond the AWS ecosystem, suggesting this is an isolated endpoint.

Recommendation: Block this IP at the perimeter firewall level. The blocking recommendation is based on the moderate risk score and DNSBL presence. If the IP represents legitimate traffic (e.g., your own AWS infrastructure), whitelist based on organizational verification before applying blocking rules.

Monitoring: Continue monitoring for any changes in threat indicators, DNSBL listings, or neighborhood activity.

---

*Intel generated by IPDebrief Intelligence Platform*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฏ๐Ÿ‡ต Japan
Region13
CityTokyo
TimezoneAsia/Tokyo
Latitude35.68
Longitude139.69

๐Ÿข Ownership & Registration

OrganizationAmazon Data Services Japan
ASNAS16509
Network NameAMAZON-NRT
CIDR Block3.112.0.0/14
RIRARIN
CountryJapan
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRec2-3-112-199-65.ap-northeast-1.compute.amazonaws.com
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesec2-3-112-199-65.ap-northeast-1.compute.amazonaws.com

๐Ÿ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 โ€” Basic operator with some routing infrastructure
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
32%
23
routing
13%
11
services
21%
22
ownership
27%
23
reputation
17%
12
geolocation
30%
23
Overall23%1014
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-29 10:34:10 UTC
Last Seen2026-08-12 23:24:24 UTC
Profile Built2026-08-12 23:55:16 UTC
Data FreshnessLive
Signal Types23
Total Observations33
๐Ÿ” 23 signal types ยท 33 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.