IP Intelligence Briefing: 34.205.18.102/32
Classification: Low Risk / AWS Cloud Infrastructure
Date: August 2026
Analyst: IPDebrief Intelligence
---
Executive Summary
IP address 34.205.18.102 is a low-risk AWS EC2 instance located in Ashburn, Virginia. The IP operates within Amazon Web Services infrastructure (ASN 14618) with a current risk score of 25/100. While flagged on one DNS blacklist with high severity, the IP demonstrates no active threat indicators, no open services, and no malicious activity in recent observations. The neighborhood classification is clean with zero abuse density in the /24 subnet.
---
Technical Profile
Network Identity:
- ASN: 14618 (Amazon Technologies Inc.)
- CIDR Block: 34.192.0.0/10
- Organization: Amazon Technologies Inc. (Netname: AT-88-Z)
- Registration: RIR ARIN
Geolocation:
- Country: United States (US)
- Region: Virginia (VA)
- City: Ashburn
- Coordinates: 39.04, -77.49
- Geo Validation: Consensus confirmed across multiple sources
Infrastructure Role:
- Cloud Provider: Amazon Web Services
- Service Status: Firewalled / No Services Detected
- No Open Ports, TLS Certificates, or HTTP Banner
- DNS Record: ec2-34-205-18-102.compute-1.amazonaws.com
---
Risk Assessment
Current Risk Score: 25/100 (Low Risk)
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
- Overall Reputation: Low Risk
Threat Indicators:
- Blacklist Status: Listed on 1 of 8 DNSBLs (Maximum Severity: High)
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Known Campaigns: None
- Threat Feeds: Empty
Control Plane:
- Route Stability: False
- BGP Prefix: 34.192.0.0/12
- DNSSEC: Valid
- DNSBL Lists: 1 listing
---
Observation History Analysis
Total Signals Observed: 22
Recent signal timeline (2026-08-13):
1. Geolocation Signal (Confidence 0.56): Ashburn, VA, US - Multi-signal inference
2. Network Classification (Confidence 0.85): AWS Cloud infrastructure, no proxy/VPN/Tor characteristics
3. DNSBL Listing (Confidence 0.85): 1 listing, maximum severity high
4. Proxy Detection (Confidence 0.85): Flagged by proxycheck-io as "Compromised Server" proxy type with risk score 83
5. Operator Score (Confidence 0.60): Basic classification, raw score 0.3
Temporal Analysis:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Persistently Malicious: No
---
Relationship Intelligence
Network Relationships:
- Primary Network: AT-88-Z (34.205.18.0/24)
- DNS Association: ec2-34-205-18-102.compute-1.amazonaws.com
No external organizational relationships detected. All relationships are internal AWS infrastructure associations.
---
Neighborhood Analysis
Subnet: 34.205.18.102/24
- Abuse Density: 0.0 (Clean)
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 0
- Risk Distribution: No high/medium risk neighbors
The IP operates in a clean subnet with no neighboring abuse activity.
---
Recommended Actions
For SOC Analysts:
1. Monitor DNSBL Listing: Investigate why the IP is listed on one DNSBL with high severity. This may require coordination with blacklist operators.
2. Verify Proxy Detection: The proxycheck-io flag showing "Compromised Server" with risk 83 warrants attention despite the overall low-risk profile. Validate if this is a false positive or indicates misconfiguration.
3. Continue Monitoring: Given the AWS cloud infrastructure nature, monitor for changes in blacklist status or proxy detection flags.
4. Network Context: No immediate blocking recommended. The IP is not showing active malicious behavior, no open services, and operates in a clean neighborhood.
Firewall Considerations:
- No immediate blocking required
- Standard logging recommended for forensic tracking
- Monitor for behavior changes if proxy detection flags persist
---
Conclusion
IP 34.205.18.102 represents standard AWS cloud infrastructure with a low overall risk profile. While the DNSBL listing and proxy detection flag require investigation, the absence of open services, zero threat persistence, and clean neighborhood metrics suggest this is likely a benign EC2 instance. Continued monitoring is recommended to validate the blacklist listing and proxy detection flag.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Technologies Inc. |
| ASN | AS16509 |
| Network Name | AT-88-Z |
| CIDR Block | 34.192.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-34-205-18-102.compute-1.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-34-205-18-102.compute-1.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 21% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-30 04:59:10 UTC |
| Last Seen | 2026-08-13 00:27:34 UTC |
| Profile Built | 2026-08-13 00:39:13 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.