IPDebrief

34.204.119.63

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 34.204.119.63/32

## Executive Summary

IP 34.204.119.63 presents a High Risk classification (score: 85) with critical threat indicators despite being hosted on Amazon Web Services infrastructure. The IP demonstrates malicious campaign associations and threat feed listings, warranting defensive scrutiny.

## Infrastructure Profile

The IP resolved to Amazon Technologies Inc. (ASN: 14618, organization: Amazon Technologies Inc.) with geolocation data indicating Waterloo, Ontario, Canada. The infrastructure operates as a web server within the Amazon Web Services network. DNS records associate the address with multiple hostnames, including ec2-34-204-119-63.compute-1.amazonaws.com and several skyjack.com domain variants.

## Threat Indicators

The IP exhibited critical risk classification on Pulsedive. Threat intelligence feeds identified the address in Feodo Tracker and Cridex IPs datasets. Campaign correlation matched the IP to Dridex and QakBot malware operations. Blacklist enumeration showed zero listings despite the elevated risk profile. The control plane demonstrated valid RPKI status and stable routing (AS Path: 1403 16509 14618).

## Network Services

Active services included HTTP (port 80), HTTPS (port 443), and SSH (port 22). The SSH banner identified OpenSSH version 7.4p1. TLS certificate analysis showed a self-signed certificate issued by LOCAL INC. in Waterloo, Ontario.

## Historical Signals

Observation history captured 100 signal instances. ASN resolution data alternated between AS14618 (Amazon-AES) and AS16509 (Amazon-02), both registered to Amazon.com, Inc. Geographic signals consistently reported US origin. The IP did not demonstrate persistent malicious behavior over the observation period.

## Network Neighborhood

The /24 subnet (34.204.119.0/24) showed an abuse density rating of 1 with mostly clean classification. Risk distribution across sibling IPs showed no high-risk neighbors. One active sibling IP registered threat indicators. The subnet contained 246 total IP addresses with 245 siblings.

## Recommended Actions

SOC analysts should monitor the IP for outbound connections related to Dridex and QakBot campaign indicators. The SSH port (22) presents an unusual exposure for web hosting infrastructure and warrants investigation. Firewall rules should consider blocking inbound SSH traffic to the address while allowing HTTPS web traffic. The IP's critical Pulsedive risk score and threat feed presence justify elevated monitoring despite the AWS infrastructure association.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡¨πŸ‡¦ Canada
RegionON
CityWaterloo
TimezoneAmerica/New_York
Latitude39.04
Longitude-77.49

🏒 Ownership & Registration

OrganizationAmazon Technologies Inc.
ASNAS14618
Network Nameβ€”
CIDR Block34.192.0.0/12
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRec2-34-204-119-63.compute-1.amazonaws.com
Forward ConfirmedYes β€” FCrDNS verified
Hosted Domainec2-34-204-119-63.compute-1.amazonaws.com
Hosted Domainskyjack.com
Hosted Domainskyworld.skyjack.com
Hosted Domainwww.skyjack.com
Hosted Domainskyjack.bwired.support
…and 2 more domains
Forward Hostnamesec2-34-204-119-63.compute-1.amazonaws.com

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierTier 2 β€” Moderate operator sophistication with routing hygiene
Cloud

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Servernginx
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_7.4p1

πŸ” TLS Certificate

A self-signed certificate was detected. This is common for development servers, internal services, or IoT devices.
⚠️
CN=*.local, O=LOCAL INC., L=Waterloo, S=Ontario, C=CA
Issued by CN=*.local, O=LOCAL INC., L=Waterloo, S=Ontario, C=CA
Self-signed: Yes
SANsNone
Valid From2026-02-11T17:49:05+00:00
Valid Until2027-02-11T17:49:05+00:00
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
Signature Algorithmsha256RSA
Validity Period365 days
Serial Number009B33DAB46A3F0591
ThumbprintD0C3342A1C45E078AD84644C36F7BB5172776DF2

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
40%
26
routing
66%
431
services
25%
23
ownership
41%
316
reputation
26%
13
geolocation
20%
23
Overall36%1462
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMixed Signals (62%) β€” 2 contradiction(s)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ RPKI is valid but IRR route object is inconsistent
⚠ Geo sources disagree on country: CA, US

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-07 23:02:59 UTC
Last Seen2026-06-26 21:56:28 UTC
Profile Built2026-06-27 15:42:19 UTC
Data FreshnessLive
Signal Types38
Total Observations109
πŸ” 38 signal types Β· 109 observations collected
This report is generated from 38+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.