# IP INTELLIGENCE BRIEFING: 3.21.76.175/32
## Executive Summary
IP address 3.21.76.175 is a cloud infrastructure endpoint belonging to Amazon Web Services (AWS) with a moderate risk classification score of 40. Analysis indicates this is a legitimate AWS EC2 instance with no active threat indicators, open services, or malicious activity patterns observed.
## Infrastructure Profile
- Organization: Amazon Technologies Inc.
- ASN: 16509 (Amazon.com Inc.)
- Network Block: 3.0.0.0/9
- Geolocation: Columbus, OH, US (39.96°N, -83.0°W)
- Hostname: ec2-3-21-76-175.us-east-2.compute.amazonaws.com
- Infrastructure Type: AWS Cloud (EC2 instance)
- Classification: Cloud infrastructure, firewalled configuration
## Network Behavior Assessment
- Service Exposure: No open ports detected; services appear fully firewalled
- DNS Resolution: Forward confirmed to AWS compute hostname
- Email Authentication: SPF and DMARC records present
- TLS: No certificates detected (typical for headless cloud instances)
- Control Plane: BGP route stable (3.20.0.0/14), RPKI state validated, route stability confirmed over 9,539 days
## Threat Intelligence Indicators
- Risk Score: 40 (Moderate Risk - primarily from control plane operator score)
- Abuse Confidence: Not applicable (no threat activity detected)
- Blacklist Status: 0 blacklist entries
- Known Campaigns: None
- Campaign Likelihood: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
## Historical Observation Summary
Analysis of 23 signal observations reveals consistent benign behavior:
- Recent probes (June 16, 2026) show port scanning activity with no open services
- Geolocation validation consistent with AWS infrastructure location
- ASN status: Assigned, stable, registry-consistent
- No persistent malicious activity patterns detected
- Threat observation count: 0
- Ownership persistence: Stable (0 changes)
## Neighborhood Analysis
- Subnet: 3.21.76.175/24
- Abuse Density: 0 (clean classification)
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 0
- No neighboring IPs flagged for abuse activity
## Relationship Graph
The IP maintains DNS associations exclusively with AWS compute hostname (ec2-3-21-76-175.us-east-2.compute.amazonaws.com) and network relationships with AT-88-Z subnet. No external organizational or certificate relationships detected.
## SOC Action Recommendations
Priority: Low / Monitor Only
- No immediate blocking required - legitimate AWS infrastructure
- Standard monitoring applies - observe for service changes or anomalous behavior
- Allow traffic through standard corporate firewall policies for AWS endpoints
- No firewall rules recommended - infrastructure appears properly secured with no open ports
## Conclusion
This IP address represents a standard AWS cloud computing endpoint with no evidence of malicious activity. The moderate risk score (40) reflects control plane data and operator scoring methodology rather than actual threat indicators. Routine monitoring is sufficient; no immediate containment or blocking actions warranted.
---
*Intelligence generated by IPDebrief. Data current as of analysis timestamp.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Technologies Inc. |
| ASN | AS16509 |
| Network Name | AT-88-Z |
| CIDR Block | 3.0.0.0/9 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-3-21-76-175.us-east-2.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-3-21-76-175.us-east-2.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 35% | 2 | 3 |
| services | 24% | 2 | 2 |
| ownership | 38% | 3 | 4 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 30% | 12 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-13 15:52:49 UTC |
| Last Seen | 2026-06-21 20:57:34 UTC |
| Profile Built | 2026-06-21 21:08:19 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 26 |
Full dossier details are available via our API.