## IP Intelligence Briefing: 3.9.189.37/32
Classification: Low Risk - Cloud Infrastructure
Report Generated: Current
Analyst: IPDebrief Intelligence
---
EXECUTIVE SUMMARY
IP address 3.9.189.37 is a low-risk AWS EC2 instance operating in London, England (eu-west-2 region). The IP maintains a risk score of 25 and shows no active threat indicators. This infrastructure is classified as cloud compute with firewalled services and no exposed ports. No immediate defensive action required.
---
OWNERSHIP & INFRASTRUCTURE
| Attribute | Value |
|---|---|
| **Organization** | Amazon Data Services UK |
| **Network Name** | AMAZON-LHR |
| **ASN** | 16509 |
| **CIDR Block** | 3.8.0.0/14 |
| **RIR** | ARIN |
| **Infrastructure Type** | Cloud Compute |
| **Service Purpose** | Firewalled / No Services |
The IP resolves to hostname `ec2-3-9-189-37.eu-west-2.compute.amazonaws.com` with confirmed forward resolution to amazonaws.com domain.
---
GEOLOCATION
| Field | Value |
|---|---|
| **Country** | United Kingdom (GB) |
| **Region** | England (ENG) |
| **City** | London |
| **Coordinates** | 51.51°N, -0.13°W |
| **Timezone** | Europe/London |
| **Geo Accuracy** | 150 km radius |
*Note: One historical observation indicated US registry allocation, but current geolocation consensus confirms UK placement.*
---
THREAT ASSESSMENT
Risk Score: 25 (Low Risk)
Reputation: Low Risk
Threat Indicators:
- No known attacker flags
- No spam source classification
- Not a Tor exit node
- No active threat campaigns detected
- 0 blacklist hits
Network Security Controls:
- DNSSEC: Valid
- RPKI State: Not assessed
- Route Stability: False
- DNSBL Listings: 1 of 8 total lists
---
NETWORK CONTEXT
Control Plane Data:
- Origin ASN: 16509
- BGP Prefix: 3.0.0.0/10
- Route Changes (30d): 0
- Operator Score: 0.2609 (Basic)
Subnet Analysis (3.9.189.37/24):
- Abuse Density: 1
- Classification: Mostly Clean
- Inherited Risk: 2
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
No neighboring IPs returned in detailed neighborhood query, indicating isolated deployment or limited sibling data.
---
OBSERVATION HISTORY
Total Observations: 19
Recent Signal Timeline:
- 2026-06-20 23:13: ASN 16509 (Amazon.com, Inc., US)
- 2026-06-20 22:51: Cloud infrastructure (AWS provider)
- 2026-06-20 22:48: Operator classification (Basic)
- 2026-06-20 22:48: Geolocation inference (London, GB)
Observations show consistent ownership and cloud infrastructure classification with no threat escalation detected.
---
RELATIONSHIP GRAPH
Total Relationships: 54
Primary Associations:
- DNS associations to `ec2-3-9-189-37.eu-west-2.compute.amazonaws.com`
- Network relationship to AMAZON-LHR
No external organization or certificate associations detected.
---
RECOMMENDED ACTIONS
Current Risk Level: Low
Recommended Actions:
- No specific firewall rules generated
- No blocking or rate-limiting required
- Monitor for service exposure if this IP transitions from cloud compute to hosting
Monitoring Triggers:
- Service port opening detection
- Reputation score degradation
- DNSBL listing increases
---
INTELLIGENCE SUMMARY
This IP address represents normal AWS cloud infrastructure with no malicious activity detected. The low risk score, absence of threat indicators, and cloud compute classification indicate legitimate infrastructure use. No immediate defensive measures are warranted. Continue monitoring for any service exposure or reputation changes.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Amazon Data Services UK |
| ASN | AS16509 |
| Network Name | AMAZON-LHR |
| CIDR Block | 3.8.0.0/14 |
| RIR | ARIN |
| Country | United Kingdom |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ec2-3-9-189-37.eu-west-2.compute.amazonaws.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ec2-3-9-189-37.eu-west-2.compute.amazonaws.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 37% | 1 | 4 |
| services | 15% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 26% | 2 | 2 |
| Overall | 26% | 10 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-25 00:41:17 UTC |
| Last Seen | 2026-06-29 00:57:28 UTC |
| Profile Built | 2026-06-29 07:00:59 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.