IP Intelligence Briefing: 3.249.242.188
Date: 2026-06-16
---
**1. Core Profile**
- Risk Assessment:
- Risk Score: 25 (Low Risk)
- Threat Indicators: No malicious activity detected (no indicators, blacklists, or campaigns).
- Network Role: Amazon Web Services (AWS) infrastructure.
- Geolocation:
- Country: Ireland (IE)
- City: Dublin
- Coordinates: 53.35°N, -6.26°E
- Accuracy: 150 km radius (inferred via DNS and BGP data).
- Ownership:
- ASN: Unregistered (AWS uses provider-based routing).
- Organization: AWS infrastructure (no direct ownership data).
---
**2. Network Behavior**
- Services:
- No open ports or active services detected.
- TLS/HTTP checks: No certificate or web server banners.
- Control Plane:
- BGP Prefix: 3.248.0.0/13 (AWS-owned range).
- Route Stability: Unstable (route changes in last 30 days).
- DNSSEC: Validated.
- DNSBL Listings: 1 out of 8 lists (low priority).
- Subnet Analysis:
- /24 Subnet: 3.249.242.0/24.
- Abuse Density: 0% (no malicious neighbors).
- Neighbors: No active sibling IPs detected (unusual for a /24 subnet).
---
**3. Temporal Observations**
- Historical Signals (Last 30 Days):
- Geolocation Consistency: Inferred as Dublin, Ireland (confidence 56%).
- Network Type: AWS cloud infrastructure (no CDN, mobile, or residential flags).
- Operator Score: 0.26 (Basic risk rating).
- Threat Persistence: No persistent malicious activity.
- Anomalies:
- Geo Plausibility: Inferred location conflicts with DNS resolution (possible false positive).
- Route Stability: Unstable BGP routes may indicate dynamic routing or misconfiguration.
---
**4. Relationships**
- DNS Associations:
- Linked to `ec2-3-249-242-188.eu-west-1.compute.amazonaws.com` (AWS EC2 instance).
- No Known Threat Associations: No subnets, organizations, or certificates tied to malicious activity.
---
**5. Recommendations**
- Monitoring:
- Track BGP route stability and geolocation consistency.
- Monitor for unexpected service exposure (e.g., open ports, TLS certificates).
- Firewall Rules:
- Allow traffic based on AWS infrastructure rules (no blocking required).
- Investigation:
- Verify geolocation discrepancies via additional DNS or traceroute analysis.
- Confirm subnet isolation (no neighbors detected may indicate a misconfigured or isolated host).
Conclusion: The IP is likely a legitimate AWS EC2 instance with no current malicious activity. However, anomalies in geolocation and routing suggest further verification is prudent.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Amazon Data Services Ireland Limited |
| ASN | AS16509 |
| Network Name | AMAZON-DUB |
| CIDR Block | 3.248.0.0/13 |
| RIR | ARIN |
| Country | Ireland |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ec2-3-249-242-188.eu-west-1.compute.amazonaws.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ec2-3-249-242-188.eu-west-1.compute.amazonaws.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 2 |
| routing | 17% | 1 | 1 |
| services | 17% | 1 | 1 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 17% | 1 | 1 |
| Overall | 21% | 8 | 10 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-09 14:18:11 UTC |
| Last Seen | 2026-06-21 16:22:35 UTC |
| Profile Built | 2026-06-21 16:46:14 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.