IPDebrief

3.252.131.227

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 3.252.131.227/32

Classification: LOW RISK | Last Updated: 2026-06-18

---

## Executive Summary

The IP address 3.252.131.227 is a low-risk AWS EC2 instance hosted in Dublin, Ireland (eu-west-1 region). No active threat indicators, malware campaigns, or abuse patterns were identified. The IP operates as a firewalled cloud compute resource with no exposed services.

---

## Threat Profile

AttributeValue
**Risk Score**25 / 100 (Low)
**Reputation**Low Risk
**ASN**16509 (Amazon.com, Inc.)
**Organization**Amazon Data Services Ireland Limited
**Geolocation**Dublin, Ireland (53.35°N, 6.26°W)
**Infrastructure Type**CloudCompute (AWS EC2)
**Blacklist Status**1 of 8 DNS blocklists

---

## Network & Infrastructure Analysis

Ownership: The IP belongs to Amazon Data Services Ireland Limited under ASN 16509. The BGP prefix 3.192.0.0/10 indicates stable AWS infrastructure routing.

DNS Resolution: Forward resolution confirms `ec2-3-252-131-227.eu-west-1.compute.amazonaws.com`. PTR record matches forward resolution (forward confirmed).

Service Exposure: No open ports detected. The profile indicates "Firewalled / No Services" with no TLS certificates, HTTP banners, or active services.

Neighborhood Assessment: The /24 subnet (3.252.131.0/24) shows 0 abuse density with clean classification. No threat siblings detected in the immediate neighborhood.

---

## Historical Intelligence

Observation History: 25 signal observations recorded from 2026-06-14 through 2026-06-18.

Temporal Analysis:

Signal Evolution: Historical data shows consistent AWS infrastructure classification with stable geolocation (Dublin, IE) and routing attributes. No significant risk escalation observed.

---

## Relationship Graph Analysis

Total Relationships: 46 links identified

Risk Implications: Relationships are consistent with legitimate AWS cloud infrastructure. No malicious peer associations detected.

---

## Recommended Security Actions

Current Risk Level: LOW (Score: 25)

Recommended Actions: None. No firewall rules, blocking recommendations, or mitigation actions are warranted based on current risk profile.

Suggested Monitoring: Standard monitoring for AWS cloud compute resources. No special threat hunting required.

---

## Intelligence Conclusion

IP 3.252.131.227 represents a legitimate AWS EC2 instance with no threat indicators. The low risk score (25), clean subnet neighborhood, absence of active services, and stable historical profile indicate this is not a threat source. SOC analysts may treat this as a benign IP address requiring only standard monitoring.

Priority: LOW | Action: None required

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฎ๐Ÿ‡ช Ireland
RegionD
CityDublin
TimezoneEurope/Dublin
Latitude53.35
Longitude-6.26

๐Ÿข Ownership & Registration

OrganizationAmazon Data Services Ireland Limited
ASNAS16509
Network Nameโ€”
CIDR Blockโ€”
RIRARIN
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRec2-3-252-131-227.eu-west-1.compute.amazonaws.com
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesec2-3-252-131-227.eu-west-1.compute.amazonaws.com

๐Ÿ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
39%
23
routing
41%
15
services
15%
22
ownership
20%
23
reputation
18%
12
geolocation
33%
23
Overall28%1018
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-07 23:04:15 UTC
Last Seen2026-06-27 04:17:29 UTC
Profile Built2026-06-27 22:23:35 UTC
Data FreshnessLive
Signal Types24
Total Observations33
๐Ÿ” 24 signal types ยท 33 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.