## Intelligence Briefing: IP 3.236.228.171/32
Executive Summary
IP address 3.236.228.171 is a low-risk EC2 cloud endpoint owned by Amazon Web Services (AWS) in Northern Virginia. The IP presents no active threat indicators and is classified as part of the Amazon-IAD (Ashburn) network infrastructure.
Key Findings
Infrastructure Classification:
- Provider: Amazon Web Services (AWS)
- Organization: Amazon Data Services Northern Virginia
- ASN: 14618 (AMAZON-AES)
- BGP Prefix: 3.224.0.0/12
- Infrastructure Type: CloudCompute
- Geolocation: Ashburn, Virginia, US (39.04°N, -77.49°W)
Risk Assessment:
- Overall Risk Score: 25 (Low Risk)
- Reputation: Low Risk
- Blacklist Status: Not listed (0 blacklists)
- Abuse Confidence: Not applicable (cloud infrastructure)
Network Services:
- Open Ports: None detected
- Service Status: Firewalled / No Services exposed
- DNS Resolution: ec2-3-236-228-171.compute-1.amazonaws.com (confirmed)
- Email Authentication: SPF and DMARC configured
Threat Indicators:
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Associations: None detected
- DNSBL Lists: 1 out of 8 lists (minor listing)
Historical Analysis
Signal observation history reveals 19 observations with consistent classification:
- Geolocation: Consistently identified as Ashburn, VA, US (confidence: 0.56)
- ASN: Confirmed as AMAZON-AES (confidence: 0.85)
- Network Role: CloudCompute infrastructure (confidence: 0.90)
- Threat Persistence: 0 days (no persistent malicious activity)
- Observation Count: 1 threat observation recorded (not persistently malicious)
Network Neighborhood Analysis
The /24 subnet (3.236.228.0/24) shows:
- Abuse Density: 1 (low)
- Classification: Mostly clean
- Inherited Risk: 2
- Threat Siblings: 1 detected in subnet
- Total Siblings: 1 active
Relationship Graph
The IP maintains 69 relationships, primarily:
- Network Associations: Multiple AMAZON-IAD network references
- DNS Associations: ec2-3-236-228-171.compute-1.amazonaws.com hostname
Recommended Actions
No specific blocking or mitigation actions recommended. This IP represents standard AWS cloud infrastructure with no evidence of malicious activity.
Assessment for SOC Analysts
This IP address is a legitimate AWS cloud endpoint with no active threat indicators. The low-risk classification (score: 25) is consistent with cloud infrastructure that may exhibit normal scanning behavior from security tools. The IP is properly firewalled with no open services and maintains valid email authentication records. No immediate action required unless correlated with other suspicious activity from the same network segment.
Classification: LOW RISK / MONITOR ONLY
Last Updated: 2026-06-26
Data Sources: IPDebrief Intelligence Platform
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services Northern Virginia |
| ASN | AS14618 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-3-236-228-171.compute-1.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-3-236-228-171.compute-1.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 20% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 24% | 1 | 3 |
| geolocation | 37% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-10 16:14:31 UTC |
| Last Seen | 2026-06-27 17:54:51 UTC |
| Profile Built | 2026-06-28 11:59:55 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 27 |
Full dossier details are available via our API.