# IP Intelligence Briefing: 34.204.119.63/32
## Executive Summary
IP 34.204.119.63 presents a High Risk classification (score: 85) with critical threat indicators despite being hosted on Amazon Web Services infrastructure. The IP demonstrates malicious campaign associations and threat feed listings, warranting defensive scrutiny.
## Infrastructure Profile
The IP resolved to Amazon Technologies Inc. (ASN: 14618, organization: Amazon Technologies Inc.) with geolocation data indicating Waterloo, Ontario, Canada. The infrastructure operates as a web server within the Amazon Web Services network. DNS records associate the address with multiple hostnames, including ec2-34-204-119-63.compute-1.amazonaws.com and several skyjack.com domain variants.
## Threat Indicators
The IP exhibited critical risk classification on Pulsedive. Threat intelligence feeds identified the address in Feodo Tracker and Cridex IPs datasets. Campaign correlation matched the IP to Dridex and QakBot malware operations. Blacklist enumeration showed zero listings despite the elevated risk profile. The control plane demonstrated valid RPKI status and stable routing (AS Path: 1403 16509 14618).
## Network Services
Active services included HTTP (port 80), HTTPS (port 443), and SSH (port 22). The SSH banner identified OpenSSH version 7.4p1. TLS certificate analysis showed a self-signed certificate issued by LOCAL INC. in Waterloo, Ontario.
## Historical Signals
Observation history captured 100 signal instances. ASN resolution data alternated between AS14618 (Amazon-AES) and AS16509 (Amazon-02), both registered to Amazon.com, Inc. Geographic signals consistently reported US origin. The IP did not demonstrate persistent malicious behavior over the observation period.
## Network Neighborhood
The /24 subnet (34.204.119.0/24) showed an abuse density rating of 1 with mostly clean classification. Risk distribution across sibling IPs showed no high-risk neighbors. One active sibling IP registered threat indicators. The subnet contained 246 total IP addresses with 245 siblings.
## Recommended Actions
SOC analysts should monitor the IP for outbound connections related to Dridex and QakBot campaign indicators. The SSH port (22) presents an unusual exposure for web hosting infrastructure and warrants investigation. Firewall rules should consider blocking inbound SSH traffic to the address while allowing HTTPS web traffic. The IP's critical Pulsedive risk score and threat feed presence justify elevated monitoring despite the AWS infrastructure association.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Technologies Inc. |
| ASN | AS14618 |
| Network Name | β |
| CIDR Block | 34.192.0.0/12 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-34-204-119-63.compute-1.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Hosted Domain | ec2-34-204-119-63.compute-1.amazonaws.com |
| Hosted Domain | skyjack.com |
| Hosted Domain | skyworld.skyjack.com |
| Hosted Domain | www.skyjack.com |
| Hosted Domain | skyjack.bwired.support |
| β¦and 2 more domains | |
| Forward Hostnames | ec2-34-204-119-63.compute-1.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 2 β Moderate operator sophistication with routing hygiene |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_7.4p1 |
π TLS Certificate
| SANs | None |
| Valid From | 2026-02-11T17:49:05+00:00 |
| Valid Until | 2027-02-11T17:49:05+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 365 days |
| Serial Number | 009B33DAB46A3F0591 |
| Thumbprint | D0C3342A1C45E078AD84644C36F7BB5172776DF2 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 6 |
| routing | 66% | 4 | 31 |
| services | 25% | 2 | 3 |
| ownership | 41% | 3 | 16 |
| reputation | 26% | 1 | 3 |
| geolocation | 20% | 2 | 3 |
| Overall | 36% | 14 | 62 |
| Data Coherence | Mixed Signals (62%) β 2 contradiction(s) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
β Geo sources disagree on country: CA, US
π Observation Timeline π Live
| First Seen | 2026-05-07 23:02:59 UTC |
| Last Seen | 2026-06-26 21:56:28 UTC |
| Profile Built | 2026-06-27 15:42:19 UTC |
| Data Freshness | Live |
| Signal Types | 38 |
| Total Observations | 109 |
Full dossier details are available via our API.