IPDebrief

3.18.108.78

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 3.18.108.78

Classification: Moderate Risk | Status: Cloud Infrastructure Host | Date: 2026-06-19

## Executive Summary

IP address 3.18.108.78 is a cloud compute resource operated by Amazon Web Services (ASN 16509) located in Columbus, OH. The IP presents moderate risk (Score: 50) with no confirmed malicious activity. OpenSSH service is active on TCP port 22. The address maintains DNSSEC validation and SPF/DMARC records, though it appears on 2 of 8 DNS blacklist lists.

## Infrastructure Profile

AttributeValue
**Organization**Amazon Technologies Inc.
**ASN**16509 (Amazon)
**Location**Columbus, OH, US
**Network Type**Cloud Compute (EC2)
**PTR Hostname**ec2-3-18-108-78.us-east-2.compute.amazonaws.com
**Open Ports**TCP/22 (SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16)

## Threat Assessment

Risk Indicators:

Control Plane Analysis:

## Historical Observations

Analysis of 25 historical observations reveals:

## Network Neighborhood

Subnet analysis for 3.18.108.78/24:

Notable Neighbor:

## Relationship Graph

The IP maintains 63 relationships including:

## Recommended Actions

For SOC Analysts:

1. Monitor, Do Not Block: The IP is legitimate AWS infrastructure with moderate risk scoring. Blocking may impact legitimate traffic.

2. Monitor Neighbor Activity: The sibling IP 3.18.108.189 shows elevated risk (40) and should be monitored separately.

3. Verify Legitimacy: Confirm EC2 instance purpose through AWS console or ticketing system if traffic appears anomalous.

4. Allowlist Consideration: If this is expected traffic, the IP may warrant allowlisting rather than blocking.

Firewall Rules:

## Conclusion

3.18.108.78 is a legitimate AWS EC2 host with standard cloud infrastructure characteristics. The moderate risk score reflects DNS blacklist presence but lacks corroborating threat indicators. No immediate blocking action required; monitor for behavioral anomalies and review the neighborhood IP 3.18.108.189 for potential elevated risk activity.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionOH
CityColumbus
TimezoneAmerica/New_York
Latitude39.96
Longitude-83.00

🏒 Ownership & Registration

OrganizationAmazon Technologies Inc.
ASNAS16509
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRec2-3-18-108-78.us-east-2.compute.amazonaws.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesec2-3-18-108-78.us-east-2.compute.amazonaws.com

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeSingle-Service Host
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
32%
24
routing
54%
112
services
15%
22
ownership
20%
23
reputation
27%
13
geolocation
23%
22
Overall29%1026
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-10 16:14:31 UTC
Last Seen2026-06-27 17:54:17 UTC
Profile Built2026-06-28 11:59:55 UTC
Data FreshnessLive
Signal Types22
Total Observations38
πŸ” 22 signal types Β· 38 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.