IPDebrief

3.114.141.120

IP Intelligence Dossier
Your IP: 216.73.217.34
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

Intelligence Briefing: 3.114.141.120/32

Summary:

The IP address 3.114.141.120/32 is a Low Risk host (Risk Score: 25) registered to Amazon Data Services Japan (ASN 16509, AMAZON-NRT). The address falls within the 3.112.0.0/14 CIDR block.

Technical Profile:

Network scans identified port 443/TCP (HTTPS) as open, operating over HTTP/2.0 with a 404 status response. DNS resolution confirmed the hostname ec2-3-114-141-120.ap-northeast-1.compute.amazonaws.com. The TLS certificate asserted Samsung, Inc. (C=KR), which conflicts with the primary geolocation attribution of Tokyo, JP. Geo-validation noted a distance violation of 9212.3 km, indicating signal contradictions between location and certificate issuer.

Threat Assessment:

No threat indicators, blacklist entries, or known campaign associations were detected. Behavioral metrics recorded zero honeypot hits, enumeration strikes, or WAF violations. The operator score is labeled as "Minimal," and DNS hygiene is rated "Good" (SPF, DMARC present).

Recommendation:

Due to the presence of signal contradictions (Geography vs. Certificate Issuer) and a Very Low confidence rating (0.125), the recommended action is to Monitor the address with Low severity.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฏ๐Ÿ‡ต Japan
Region13
CityTokyo
TimezoneAsia/Tokyo
Latitude35.68
Longitude139.69

๐Ÿข Ownership & Registration

OrganizationAmazon Data Services Japan
ASNAS16509
Network NameAMAZON-NRT
CIDR Block3.112.0.0/14
RIRARIN
CountryJapan
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRec2-3-114-141-120.ap-northeast-1.compute.amazonaws.com
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesec2-3-114-141-120.ap-northeast-1.compute.amazonaws.com

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECNot signed
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
443httpstcpโ€”
Closed Ports22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

A self-signed certificate was detected. This is common for development servers, internal services, or IoT devices.
โš ๏ธ
CN=HRM_SSM Primary Root CA, OU="(c) 2017 HRM_SSM, Inc. - For authorized use only", OU=Certification Services Division, O="Samsung, Inc.", C=KR, CN=*.samsunghrm.com
Issued by CN=HRM_SSM Primary Root CA, OU="(c) 2017 HRM_SSM, Inc. - For authorized use only", OU=Certification Services Division, O="Samsung, Inc.", C=KR, CN=*.samsunghrm.com
Self-signed: Yes
SANs*.samsunghrm.comlocalhost127.0.0.1
Valid From2018-08-08T02:06:36+00:00
Valid Until2048-07-31T02:06:36+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_128_GCM_SHA256
Signature Algorithmsha256RSA
Validity Period10950 days
Serial Number00D5D3DFC69D30EFC6
Thumbprint167FBA5653F787D5092C6FEAC3879D24B4CAF82F

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
0%
00
Overall12%33
Coverage: 3/6 dimensions ยท Data sufficiency: partial
Data CoherenceMixed Signals (68%) โ€” 2 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Geo sources disagree on country: US, JP, KR
โš  TLS certificate claims KR but primary geo says JP

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-09-19 05:17:49 UTC
Last Seen2026-09-19 05:17:49 UTC
Profile Built2026-09-19 05:30:56 UTC
Data FreshnessLive
Signal Types25
Total Observations25
๐Ÿ” 25 signal types ยท 25 observations collected
This report is generated from 25+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.