# IP Intelligence Briefing: 3.252.197.176
Classification: Cloud Infrastructure (Amazon Web Services)
Report Date: Current
Risk Assessment: LOW RISK (Score: 25)
---
## Executive Summary
IP 3.252.197.176 is a legitimate Amazon Web Services (AWS) cloud compute instance hosted in the Dublin, Ireland region (EU-West-1). The IP presents a low threat profile with no active malicious indicators. Classification as cloud infrastructure indicates this is part of AWS's global infrastructure network, not a residential or compromised endpoint.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **IP Address** | 3.252.197.176/32 |
| **Organization** | Amazon Data Services Ireland Limited |
| **ASN** | AS16509 |
| **Location** | Dublin, Ireland (53.35°N, 6.26°W) |
| **CIDR Block** | 3.248.0.0/13 |
| **Network Role** | Cloud Compute |
| **Infrastructure Type** | Cloud Infrastructure |
DNS Resolution: ec2-3-252-197-176.eu-west-1.compute.amazonaws.com (confirmed forward resolution)
---
## Threat Indicators
- Abuse Confidence Score: Not available
- Blacklist Count: 0
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Threat Campaigns: None detected
- Open Ports: None detected
- Active Services: None detected
The IP shows no active threat indicators in the current threat feed analysis. No TLS certificates, HTTP services, or server banners detected.
---
## Historical Activity
Total Observations: 21 signals recorded
Recent activity includes:
- Port scanning activity detected
- Multiple blacklist listings observed (8 total DNSBL lists)
- Proxy/VPN classification signals from third-party sources (proxycheck-io)
- No persistent malicious behavior identified
The historical signal count indicates monitoring activity but no confirmed malicious persistence.
---
## Network Context
Neighborhood Analysis (3.252.197.0/24):
- Subnet Classification: Clean
- Abuse Density: 0.00%
- High-Risk Neighbors: 0
- Medium-Risk Neighbors: 0
- Low-Risk Neighbors: 0
- Total Active Siblings: 1
The /24 subnet shows zero abuse density, indicating this is part of AWS's standard cloud infrastructure with no adjacent malicious activity.
---
## Relationship Graph
Total Relationships: 71
Key associations:
- DNS: ec2-3-252-197-176.eu-west-1.compute.amazonaws.com
- Network: AMAZON-DUB (AWS Dublin network)
- Multiple same-network associations with other AWS Dublin infrastructure
All relationships align with expected AWS infrastructure patterns.
---
## Recommended Actions
Current Risk Level: 25 (Low)
Firewall/Blocking Recommendation: NO ACTION REQUIRED
This IP is a legitimate AWS cloud instance. No blocking is recommended. Standard cloud security policies (rate limiting, geo-blocking if applicable to EU-West-1) should apply. No specific firewall rules generated due to low-risk classification.
Monitoring Guidance:
- Treat as legitimate cloud infrastructure
- Apply standard cloud provider security policies
- No additional blocking or allowlisting required
- Monitor for unexpected behavior patterns (as with all cloud resources)
---
## Risk Conclusion
IP 3.252.197.176 is a legitimate Amazon Web Services cloud compute instance with no current threat indicators. The IP is part of AWS's Dublin infrastructure network and presents standard cloud security characteristics. SOC analysts should treat this as benign cloud infrastructure and apply standard cloud provider security policies. No immediate action or blocking is required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Amazon Data Services Ireland Limited |
| ASN | AS16509 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ec2-3-252-197-176.eu-west-1.compute.amazonaws.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ec2-3-252-197-176.eu-west-1.compute.amazonaws.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_7.4 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 18% | 1 | 2 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 18% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-15 14:46:10 UTC |
| Last Seen | 2026-06-28 02:26:12 UTC |
| Profile Built | 2026-06-28 20:31:00 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 27 |
Full dossier details are available via our API.