# IP Intelligence Briefing: 3.18.108.78
Classification: Moderate Risk | Status: Cloud Infrastructure Host | Date: 2026-06-19
## Executive Summary
IP address 3.18.108.78 is a cloud compute resource operated by Amazon Web Services (ASN 16509) located in Columbus, OH. The IP presents moderate risk (Score: 50) with no confirmed malicious activity. OpenSSH service is active on TCP port 22. The address maintains DNSSEC validation and SPF/DMARC records, though it appears on 2 of 8 DNS blacklist lists.
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **Organization** | Amazon Technologies Inc. |
| **ASN** | 16509 (Amazon) |
| **Location** | Columbus, OH, US |
| **Network Type** | Cloud Compute (EC2) |
| **PTR Hostname** | ec2-3-18-108-78.us-east-2.compute.amazonaws.com |
| **Open Ports** | TCP/22 (SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16) |
## Threat Assessment
Risk Indicators:
- Reputation: Moderate Risk (Score: 50)
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Status: Listed on 2 of 8 DNS blacklist feeds
- Abuse Confidence: Not applicable (cloud infrastructure)
Control Plane Analysis:
- BGP Prefix: 3.16.0.0/14
- Route Stability: False (route changes observed)
- DNSSEC Valid: Yes
- Operator Score: 0.2609 (Basic)
- RPKI State: Not available
## Historical Observations
Analysis of 25 historical observations reveals:
- Recent activity detected on 2026-06-19
- DNS blacklist listings active on 1 of 8 total lists
- Operator score maintained at 0.2609 (Basic)
- No persistent malicious behavior observed
- Subnet abuse density: 0.5 (moderate)
## Network Neighborhood
Subnet analysis for 3.18.108.78/24:
- Total Siblings: 2
- Threat Siblings: 1 (3.18.108.189, Risk Score: 40)
- Abuse Density: 0.5
- Classification: Mostly Clean
Notable Neighbor:
- 3.18.108.189: Risk Score 40, Authority Score 60
## Relationship Graph
The IP maintains 63 relationships including:
- DNS associations to ec2-3-18-108-78.us-east-2.compute.amazonaws.com
- Network relationships to AT-88-Z
- No certificate-based relationships detected
## Recommended Actions
For SOC Analysts:
1. Monitor, Do Not Block: The IP is legitimate AWS infrastructure with moderate risk scoring. Blocking may impact legitimate traffic.
2. Monitor Neighbor Activity: The sibling IP 3.18.108.189 shows elevated risk (40) and should be monitored separately.
3. Verify Legitimacy: Confirm EC2 instance purpose through AWS console or ticketing system if traffic appears anomalous.
4. Allowlist Consideration: If this is expected traffic, the IP may warrant allowlisting rather than blocking.
Firewall Rules:
- No blocking rules recommended
- Consider rate limiting SSH traffic if not expected internally
- Monitor for port scanning activity from this IP to your infrastructure
## Conclusion
3.18.108.78 is a legitimate AWS EC2 host with standard cloud infrastructure characteristics. The moderate risk score reflects DNS blacklist presence but lacks corroborating threat indicators. No immediate blocking action required; monitor for behavioral anomalies and review the neighborhood IP 3.18.108.189 for potential elevated risk activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Technologies Inc. |
| ASN | AS16509 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-3-18-108-78.us-east-2.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-3-18-108-78.us-east-2.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 4 |
| routing | 54% | 1 | 12 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 27% | 1 | 3 |
| geolocation | 23% | 2 | 2 |
| Overall | 29% | 10 | 26 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-10 16:14:31 UTC |
| Last Seen | 2026-06-27 17:54:17 UTC |
| Profile Built | 2026-06-28 11:59:55 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 38 |
Full dossier details are available via our API.