Threat Intelligence Briefing: IP 34.146.217.105/32
General Information:
- IP Address: 34.146.217.105/32
- Organization: This IP address is associated with Amazon Web Services (AWS). Specifically, it is part of the IP address ranges used by AWS for their services, which are dynamically allocated and can host a wide variety of applications and services.
Observation History:
- The IP address 34.146.217.105 has been observed to host a range of services as part of its dynamic nature within the AWS ecosystem. It has been used for various legitimate services, including web hosting, application servers, and other cloud-based operations.
Relationships:
- Parent Organization: Amazon.com, Inc. (AWS)
- Service Types: The IP address may host services such as web applications, APIs, or other cloud-based resources. It is part of a broader set of AWS IP ranges that are frequently updated to reflect changes in AWS infrastructure and services.
Neighborhood Data:
- IP Range Context: The IP address is within a larger range of AWS IP addresses, which are known for their dynamic allocation. This means that the specific services hosted at this IP address can change frequently.
- Neighboring IPs: Other IPs in the same range are similarly used by AWS for various cloud services, making it challenging to attribute specific activities to a single IP without further context.
Security Considerations:
- Dynamic Nature: Due to the dynamic allocation of AWS IP addresses, monitoring and attribution to specific services or users require additional contextual information beyond just the IP address.
- Potential Threats: While the IP address itself is legitimate, it is essential to monitor for unusual activity or patterns that could indicate misuse, such as unexpected data exfiltration or unauthorized access attempts.
- Access Control: Ensure that access to services hosted on this IP address is secured with appropriate authentication and authorization measures to prevent unauthorized access.
Actionable Recommendations:
1. Monitor Traffic Patterns: Regularly monitor traffic to and from this IP address for any anomalies that could indicate a security incident.
2. Service Identification: Use additional tools or logs to identify specific services hosted on this IP to better understand the context of its usage.
3. Implement Security Controls: Apply security controls such as firewalls, intrusion detection systems (IDS), and logging to detect and respond to potential threats.
4. Stay Updated: Keep track of AWS IP range updates to understand changes in the infrastructure that might affect security postures.
This briefing provides a comprehensive overview of the IP address 34.146.217.105/32, emphasizing its association with AWS and the need for vigilant monitoring and security practices.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | β |
| CIDR Block | 34.146.208.0/20 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 105.217.146.34.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 105.217.146.34.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| 8080 | http-alt | tcp | β |
| Closed Ports | 25, 80, 443, 3389, 8443 (2 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_7.2p2 Ubuntu-4ubuntu2.2 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 21% | 2 | 4 |
| routing | 17% | 2 | 3 |
| services | 17% | 2 | 3 |
| ownership | 22% | 3 | 4 |
| reputation | 26% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 22% | 12 | 20 |
| Data Coherence | Mixed Signals (65%) β 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
β Geo sources disagree on country: JP, US
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:16 UTC |
| Last Seen | 2026-06-27 04:25:32 UTC |
| Profile Built | 2026-06-27 22:32:00 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 33 |
Full dossier details are available via our API.