Intelligence Briefing: 3.136.62.26
The target IP 3.136.62.26 was identified as a Web Server within Amazon Web Services infrastructure (ASN 16509, Amazon Technologies Inc.). Forward DNS resolution confirmed the hostname `ec2-3-136-62-26.us-east-2.compute.amazonaws.com`. The system operated standard HTTPS service on TCP port 443.
TLS handshake data revealed a certificate issued by Samsung Electronics OCF Server SubCA for the domain `*.samsungiotcloud.com`. Geolocation analysis presented conflicting indicators; primary sources localized the host to Columbus, OH, US, while the TLS certificate issuer country (KR) and secondary geo sources indicated Republic of Korea. Control plane analysis showed one DNSBL listing among eight checked lists, though the overall blacklist count remained at zero. Behavioral analysis recorded zero total incidents and zero honeypot strikes. The threat profile was classified as Low Risk with a risk score of 25. No active attacker status or known campaigns were associated with the address. Due to signal contradictions regarding geographic origin, the recommended action was to Monitor.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Technologies Inc. |
| ASN | AS16509 |
| Network Name | AT-88-Z |
| CIDR Block | 3.128.0.0/9 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-3-136-62-26.us-east-2.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-3-136-62-26.us-east-2.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | *.samsungiotcloud.com |
| Valid From | 2020-03-18T07:40:32+00:00 |
| Valid Until | 2035-04-09T07:40:32+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256ECDSA |
| Validity Period | 5500 days |
| Serial Number | 33DEF0C83047D74E |
| Thumbprint | 30AA82E4144123E889C449CD1F47CDC2F811A97D |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Mixed Signals (68%) β 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
β TLS certificate claims KR but primary geo says US
π Observation Timeline π Live
| First Seen | 2026-09-15 01:35:53 UTC |
| Last Seen | 2026-09-15 01:35:53 UTC |
| Profile Built | 2026-09-15 01:48:17 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 25 |
Full dossier details are available via our API.