# IP Intelligence Briefing: 3.129.92.250/32
## Executive Summary
IP 3.129.92.250 is a low-risk (25) Amazon Web Services (AWS) EC2 instance located in the US East (Ohio) region. The address is classified as cloud infrastructure with minimal threat indicators. No immediate blocking is recommended, but monitoring for DNSBL listings and SSH traffic is advised.
## Ownership and Infrastructure
- Organization: Amazon Technologies Inc. (ASN 16509)
- Network Block: 3.128.0.0/9 (AT-88-Z)
- Infrastructure Type: CloudCompute (AWS EC2)
- Service Purpose: Single-Service Host
- Infrastructure Classification: Cloud hosting environment
## Geolocation Data
- Country: United States (US)
- Region/State: Ohio (OH)
- City: Columbus
- Coordinates: 39.96, -83.00
- Timezone: America/New_York
## Network Services
- Open Ports: TCP/22 (SSH)
- SSH Banner: SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16
- DNS Resolution: ec2-3-129-92-250.us-east-2.compute.amazonaws.com
- DNSSEC: Valid
## Threat Intelligence Profile
- Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not applicable
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0
- Known Campaigns: None detected
- Threat Feeds: Empty
## Control Plane Analysis
- Origin ASN: 16509 (Amazon.com, Inc.)
- BGP Prefix: 3.128.0.0/15
- Route Stability: Unstable (isRouteStable: false)
- DNSSEC Validation: Valid
- DNSBL Listings: 1 of 8 lists (minor concern)
- RPKI State: Not configured
- IRR Consistency: Not configured
## Neighborhood Analysis
- Subnet: 3.129.92.250/24
- Abuse Density: 0%
- Classification: Clean
- High Risk Neighbors: 0
- Medium Risk Neighbors: 0
- Low Risk Neighbors: 0
- Threat Siblings: 0
## Observation History
- Total Observations: 22
- Recent Activity: Signals detected on 2026-06-21
- Signal Types: ASN, geolocation, DNS, routing, services, reputation
- Threat Persistence: 0 days (not persistently malicious)
- Ownership Changes: 0
## Relationship Graph
- Total Relationships: 41
- Same Network: AT-88-Z (Amazon network)
- DNS Associations: ec2-3-129-92-250.us-east-2.compute.amazonaws.com
- Related Entities: Multiple network-level associations
## Geo Validation Alert
- Distance Discrepancy: 6,580.9 km
- RTT Violation: 37ms minimum RTT is below the theoretical minimum of 131.6ms for the reported distance
- Impact: This suggests potential geolocation inference inaccuracy or probe routing anomalies
## Recommended Actions
No immediate security actions are required. The following monitoring recommendations apply:
1. Monitor DNSBL Listings: Track the single DNSBL listing across the 8 total lists
2. SSH Traffic Analysis: Monitor inbound SSH traffic for anomalous patterns
3. Route Stability: Investigate BGP route instability (isRouteStable: false)
4. Geo Validation: Consider alternative geolocation sources due to RTT/distance discrepancy
## Conclusion
IP 3.129.92.250 represents a legitimate AWS cloud infrastructure endpoint with low-risk characteristics. The address exhibits standard cloud computing behavior with no evidence of malicious activity. The RTT/distance validation discrepancy and minor DNSBL listing warrant routine monitoring but do not indicate active threat activity. No firewall rules or blocking recommendations are generated at this time.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Technologies Inc. |
| ASN | AS16509 |
| Network Name | AT-88-Z |
| CIDR Block | 3.128.0.0/9 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-3-129-92-250.us-east-2.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-3-129-92-250.us-east-2.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 24% | 2 | 3 |
| Overall | 20% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-29 18:14:58 UTC |
| Last Seen | 2026-06-29 06:39:24 UTC |
| Profile Built | 2026-06-29 07:00:59 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 30 |
Full dossier details are available via our API.