IPDebrief

34.205.18.102

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP Intelligence Briefing: 34.205.18.102/32

Classification: Low Risk / AWS Cloud Infrastructure

Date: August 2026

Analyst: IPDebrief Intelligence

---

Executive Summary

IP address 34.205.18.102 is a low-risk AWS EC2 instance located in Ashburn, Virginia. The IP operates within Amazon Web Services infrastructure (ASN 14618) with a current risk score of 25/100. While flagged on one DNS blacklist with high severity, the IP demonstrates no active threat indicators, no open services, and no malicious activity in recent observations. The neighborhood classification is clean with zero abuse density in the /24 subnet.

---

Technical Profile

Network Identity:

Geolocation:

Infrastructure Role:

---

Risk Assessment

Current Risk Score: 25/100 (Low Risk)

Threat Indicators:

Control Plane:

---

Observation History Analysis

Total Signals Observed: 22

Recent signal timeline (2026-08-13):

1. Geolocation Signal (Confidence 0.56): Ashburn, VA, US - Multi-signal inference

2. Network Classification (Confidence 0.85): AWS Cloud infrastructure, no proxy/VPN/Tor characteristics

3. DNSBL Listing (Confidence 0.85): 1 listing, maximum severity high

4. Proxy Detection (Confidence 0.85): Flagged by proxycheck-io as "Compromised Server" proxy type with risk score 83

5. Operator Score (Confidence 0.60): Basic classification, raw score 0.3

Temporal Analysis:

---

Relationship Intelligence

Network Relationships:

No external organizational relationships detected. All relationships are internal AWS infrastructure associations.

---

Neighborhood Analysis

Subnet: 34.205.18.102/24

The IP operates in a clean subnet with no neighboring abuse activity.

---

Recommended Actions

For SOC Analysts:

1. Monitor DNSBL Listing: Investigate why the IP is listed on one DNSBL with high severity. This may require coordination with blacklist operators.

2. Verify Proxy Detection: The proxycheck-io flag showing "Compromised Server" with risk 83 warrants attention despite the overall low-risk profile. Validate if this is a false positive or indicates misconfiguration.

3. Continue Monitoring: Given the AWS cloud infrastructure nature, monitor for changes in blacklist status or proxy detection flags.

4. Network Context: No immediate blocking recommended. The IP is not showing active malicious behavior, no open services, and operates in a clean neighborhood.

Firewall Considerations:

---

Conclusion

IP 34.205.18.102 represents standard AWS cloud infrastructure with a low overall risk profile. While the DNSBL listing and proxy detection flag require investigation, the absence of open services, zero threat persistence, and clean neighborhood metrics suggest this is likely a benign EC2 instance. Continued monitoring is recommended to validate the blacklist listing and proxy detection flag.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionVA
CityAshburn
TimezoneAmerica/New_York
Latitude39.04
Longitude-77.49

🏒 Ownership & Registration

OrganizationAmazon Technologies Inc.
ASNAS16509
Network NameAT-88-Z
CIDR Block34.192.0.0/10
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRec2-34-205-18-102.compute-1.amazonaws.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesec2-34-205-18-102.compute-1.amazonaws.com

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 β€” Basic operator with some routing infrastructure
Cloud

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
23
routing
13%
11
services
19%
22
ownership
27%
23
reputation
15%
12
geolocation
27%
23
Overall21%1014
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-30 04:59:10 UTC
Last Seen2026-08-13 00:27:34 UTC
Profile Built2026-08-13 00:39:13 UTC
Data FreshnessLive
Signal Types22
Total Observations23
πŸ” 22 signal types Β· 23 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.