IP 3.12.234.189 was identified as a low-risk address with a risk score of 0. The infrastructure is owned by Amazon Technologies Inc. (AS16509) and resolves to ec2-3-12-234-189.us-east-2.compute.amazonaws.com within the US-East-2 region. Port 443 (HTTPS) was observed active, serving a TLS certificate issued by Samsung Electronics for *.samsungiotcloud.com.
Threat intelligence feeds returned no indicators for known attackers, spam sources, or Tor exit nodes. The neighborhood analysis classified the /24 subnet as clean with zero threat siblings. However, data contradictions were noted regarding geolocation, with sources disagreeing between the US and South Korea. Additionally, the TLS certificate subject indicated South Korea, conflicting with the primary US geolocation.
The recommendation was to monitor the address due to signal contradictions. No immediate blocking action was required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Technologies Inc. |
| ASN | AS16509 |
| Network Name | AT-88-Z |
| CIDR Block | 3.0.0.0/9 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-3-12-234-189.us-east-2.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-3-12-234-189.us-east-2.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 3/3 domains |
| DMARC | 2/3 domains |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 3 domains |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 2 β Moderate operator sophistication with routing hygiene |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | *.samsungiotcloud.com |
| Valid From | 2020-03-18T07:40:32+00:00 |
| Valid Until | 2035-04-09T07:40:32+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256ECDSA |
| Validity Period | 5500 days |
| Serial Number | 33DEF0C83047D74E |
| Thumbprint | 30AA82E4144123E889C449CD1F47CDC2F811A97D |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 43% | 2 | 5 |
| routing | 38% | 4 | 5 |
| services | 27% | 2 | 3 |
| ownership | 30% | 3 | 4 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 4 |
| Overall | 33% | 14 | 24 |
| Data Coherence | Mixed Signals (68%) β 2 contradiction(s) |
| Attribution | High (85%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
β TLS certificate claims KR but primary geo says US
π Observation Timeline π Live
| First Seen | 2026-09-07 22:45:10 UTC |
| Last Seen | 2026-09-21 18:28:15 UTC |
| Profile Built | 2026-09-21 18:46:12 UTC |
| Data Freshness | Live |
| Signal Types | 31 |
| Total Observations | 43 |
Full dossier details are available via our API.